Vulnerabilities > Samba > Samba > 4.0.18

DATE CVE VULNERABILITY TITLE RISK
2015-01-17 CVE-2014-8143 Permissions, Privileges, and Access Controls vulnerability in Samba
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
network
samba CWE-264
8.5
2014-06-23 CVE-2014-0244 Improper Input Validation vulnerability in Samba
The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.
low complexity
samba CWE-20
3.3