← All CVEs

CVE-2004-0882

high · 10

Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.

10
CVSS
13.7%
EPSS (exploit prob.)
96th
EPSS percentile
2005-01-27
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
sambasamba3.0.0
sambasamba3.0.1
sambasamba3.0.2
sambasamba3.0.2a
sambasamba3.0.3
sambasamba3.0.4
sambasamba3.0.4
sambasamba3.0.5
sambasamba3.0.6
sambasamba3.0.7
conectivalinux10.0
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux3.0
redhatenterprise_linux3.0
redhatenterprise_linux3.0
redhatenterprise_linux_desktop3.0
redhatfedora_corecore_2.0
redhatfedora_corecore_3.0
redhatlinux_advanced_workstation2.1
redhatlinux_advanced_workstation2.1
ubuntuubuntu_linux4.1
ubuntuubuntu_linux4.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0882