Search CVE reports


Toggle filters

111 – 120 of 199 results


CVE-2016-2125

Medium priority

Some fixes available 5 of 6

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2123

High priority

Some fixes available 4 of 5

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2119

Medium priority

Some fixes available 2 of 4

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers,...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2118

Medium priority

Some fixes available 6 of 7

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2115

Medium priority

Some fixes available 6 of 7

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying...

2 affected packages

samba4, samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba4
samba
Show less packages

CVE-2016-2114

Medium priority

Some fixes available 5 of 6

The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2113

Medium priority

Some fixes available 5 of 6

Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2112

Medium priority

Some fixes available 6 of 7

The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2111

Medium priority

Some fixes available 6 of 7

The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2110

Medium priority

Some fixes available 6 of 7

The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data...

2 affected packages

samba, samba4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages