<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:08:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00684</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00684</link>
      <description>bdu:2022-00684</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00684</guid>
    </item>
    <item>
      <title>certfr-2022-avi-096 — De multiples vulnérabilités ont été découvertes dans Samba. Certaines
d'entre elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-096</link>
      <description>certfr-2022-avi-096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-096</guid>
    </item>
    <item>
      <title>EUVD-2026-10863</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-10863</link>
      <description>EUVD-2026-10863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-10863</guid>
    </item>
    <item>
      <title>fkie_cve-2022-0336</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-0336</link>
      <description>&lt;p&gt;The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-0336</guid>
    </item>
    <item>
      <title>GHSA-rg44-hwh5-vcpq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rg44-hwh5-vcpq</link>
      <description>&lt;p&gt;The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rg44-hwh5-vcpq</guid>
    </item>
    <item>
      <title>gsd-2022-0336</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-0336</link>
      <description>gsd-2022-0336</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-0336</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-0336 — The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not al…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-0336</link>
      <description>msrc_CVE-2022-0336</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-0336</guid>
    </item>
    <item>
      <title>OESA-2022-1529 — samba security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: samba, openEuler:20.03-LTS-SP2: samba, openEuler:20.03-LTS-SP3: samba&lt;/p&gt;
&lt;p&gt;Samba is a suite of programs for Linux and Unix to interoperate with Windows.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Checks in Samba AD DC to prevent alias SPNs may be bypassed, enabling users who can write to the account&amp;#39;s servicePrincipalName attribute to impersonate the service.(CVE-2022-0336)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: samba, openEuler:20.03-LTS-SP2: samba, openEuler:20.03-LTS-SP3: samba&lt;/p&gt;
&lt;p&gt;Samba is a suite of programs for Linux and Unix to interoperate with Windows.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Checks in Samba AD DC to prevent alias SPNs may be bypassed, enabling users who can write to the account&amp;#39;s servicePrincipalName attribute to impersonate the service.(CVE-2022-0336)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1529</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-0336</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0336</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: samba&lt;/p&gt;
&lt;p&gt;The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: samba&lt;/p&gt;
&lt;p&gt;The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0336</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
