Vulnerabilities
Vulnerable Software
Samba:  >> Samba  >> 3.0.20b  Security Vulnerabilities
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
CVSS Score
6.0
EPSS Score
0.727
Published
2007-05-14
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
CVSS Score
6.8
EPSS Score
0.025
Published
2007-02-06
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.
CVSS Score
7.5
EPSS Score
0.049
Published
2007-02-06
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
CVSS Score
5.0
EPSS Score
0.298
Published
2006-07-12


Contact Us

Shodan ® - All rights reserved