Known vulnerabilities in samba (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:samba_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 41
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting samba (Red Hat package) samba (Red Hat package) is affected by 41 known vulnerabilities: 11 high, 20 medium, 10 low Critical High Medium Low

Vulnerabilities (41)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU60186 - Out-of-bounds write
CVE-2021-44142
CWE-787 High
Available
No
4.8.3-7.el7_6, 4.9.1-12.el7_7, 4.10.4-103.el8_1, 4.10.16-18.el7_9, 4.11.2-19.el8_2, 4.11.6-116.el7rhgs, 4.13.3-9.el8_4, 4.14.5-9.el8_5, 4.14.5-206.el8rhgs 31.01.2022 SB2022013111
SB2022013118
SB2022013119
and 36 more
#VU59345 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-43566
CWE-59 Low
No
No
4.14.5-2.el8 10.01.2022 SB2022011006
SB2022041954
SB2022020185
and 7 more
#VU58098 - Improper Access Control
CVE-2016-2124
CWE-284 High
No
No
4.10.16-17.el7_9, 4.11.2-18.el8_2, 4.11.6-114.el7rhgs, 4.13.3-8.el8_4, 4.14.5-7.el8_5, 4.14.5-204.el8rhgs 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 34 more
#VU58097 - Permissions, Privileges, and Access Controls
CVE-2020-25717
CWE-264 Medium
No
No
4.10.16-17.el7_9, 4.10.16-18.el7_9, 4.11.2-18.el8_2, 4.11.6-114.el7rhgs, 4.13.3-8.el8_4, 4.13.3-9.el8_4, 4.14.5-7.el8_5, 4.14.5-9.el8_5, 4.14.5-204.el8rhgs 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 43 more
#VU58091 - Improper input validation
CVE-2021-23192
CWE-20 Medium
No
No
4.13.3-8.el8_4, 4.14.5-7.el8_5, 4.14.5-204.el8rhgs 10.11.2021 SB2021111008
SB2021111201
SB2021112914
and 19 more
#VU52748 - Out-of-bounds read
CVE-2021-20254
CWE-125 Medium
No
No
4.9.1-11.el7_7, 4.10.16-15.el7_9, 4.11.2-15.el8_2, 4.11.6-112.el7rhgs, 4.13.3-5.el8_4, 4.14.5-201.el8rhgs 29.04.2021 SB2021042916
SB2021052619
SB2021060941
and 30 more
#VU47991 - NULL Pointer Dereference
CVE-2020-14323
CWE-476 Medium
No
No
4.10.16-9.el7_9, 4.11.6-112.el7rhgs, 4.13.3-3.el8, 4.13.7-101.el8rhgs 29.10.2020 SB2020102935
SB2020110205
SB2020110211
and 18 more
#VU47990 - Permissions, Privileges, and Access Controls
CVE-2020-14318
CWE-264 Low
No
No
4.10.16-9.el7_9, 4.11.6-112.el7rhgs, 4.13.3-3.el8, 4.13.7-101.el8rhgs 29.10.2020 SB2020102935
SB2020110205
SB2020110211
and 17 more
#VU45628 - Permissions, Privileges, and Access Controls
CVE-2020-1472
CWE-264 High
Available
Exploited
4.10.16-9.el7_9, 4.11.6-112.el7rhgs, 4.13.3-3.el8, 4.13.7-101.el8rhgs 12.08.2020 SB2020081242
SB2020091810
SB2020092413
and 22 more
#VU29483 - NULL Pointer Dereference
CVE-2020-10730
CWE-476 Medium
No
No
4.11.6-107.el7rhgs, 4.11.6-107.el8rhgs 02.07.2020 SB2020070224
SB2020071805
SB2020072104
and 12 more
#VU24466 - Improper input validation
CVE-2019-14907
CWE-20 Medium
No
No
4.11.2-13.el8, 4.11.6-104.el7rhgs 21.01.2020 SB2020012110
SB2020012301
SB2020012905
and 10 more
#VU22329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-10218
CWE-22 Medium
No
No
4.11.2-13.el8, 4.11.6-104.el7rhgs 29.10.2019 SB2019102910
SB2019103005
SB2019110304
and 13 more
#VU20809 - Permissions, Privileges, and Access Controls
CVE-2019-10197
CWE-264 Medium
No
No
4.11.2-13.el8 03.09.2019 SB2019090302
SB2019090424
SB2019090308
and 13 more
#VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2118
CWE-300 High
No
No
3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2115
CWE-300 Medium
No
No
3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2114
CWE-300 Medium
No
No
4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 11 more
#VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2113
CWE-300 Medium
No
No
4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 16 more
#VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2112
CWE-300 Medium
No
No
3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU236 - Authentication Bypass by Spoofing
CVE-2016-2111
CWE-290 Medium
No
No
3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2110
CWE-300 Medium
No
No
3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more


Showing elements 21 - 40 out of 41