CVEs (31)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
2Redhat Samba8Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems+5 moreJun 17, 2026 Nov 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The...Show more |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote...Show more |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes"....Show more |
3Fedoraproject RedhatSamba4Enterprise Linux FedoraSamba+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 pack...Show more |
4Debian FedoraprojectRedhat+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a...Show more |
2Openstack Redhat4Keystone Openstack PlatformQuay+1 moreJun 17, 2026 Sep 1, 2022 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote admini...Show more |
3Fedoraproject RedhatSamba3Fedora SambaStorageJun 17, 2026 Aug 23, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 MaxQueryDuration not honoured in Samba AD DC LDAP |
2Grafana Redhat3Ceph Storage GrafanaStorageJun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can righ...Show more |
3Fedoraproject RedhatSamba3Fedora SambaStorageJun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. S...Show more |
2Redhat Samba3Enterprise Linux SambaStorageJun 17, 2026 Dec 3, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the att...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise...Show more |
2Debian Redhat6Ansible Engine Ansible TowerCeph Storage+3 moreJun 17, 2026 May 11, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 whe...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux Directory ServerDiskstation Manager+7 moreJun 17, 2026 Jan 21, 2020 N/A· v4 6.5 MEDIUM· v3 2.6 LOW· v2 All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character c...Show more |
1Redhat 3Enterprise Virtualization StorageVirtual Desktop Server ManagerNov 21, 2024 Nov 4, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Insecure temporary file vulnerability in RedHat vsdm 4.9.6. |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of s...Show more |
9Fedoraproject Filezilla ProjectMariadb+6 more16Application Processing Engine Firmware Cp1543 1 FirmwareEnterprise Linux+13 moreMay 6, 2026 Jun 5, 2014 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS he...Show more |
13Broadcom CanonicalDebian+10 more28Application Processing Engine Firmware Cp 1543 1 FirmwareDebian Linux+25 moreApr 21, 2026 Apr 7, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted pa...Show more |
3Fedoraproject OpenstackRedhat7Enterprise Linux Server FedoraGluster Storage Management Console+4 moreApr 29, 2026 Oct 22, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a cra...Show more |