CVEPublished 2014-05-28Modified 2026-05-060 articles on news7 live referencesNVD data

CVE-2014-0178Samba · Samba

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
Description

Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.

Timeline
Published 2014-05-28
Modified 2026-05-06

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2014-0178 on GitHub.
We haven't classified any articles referencing CVE-2014-0178 yet. The external references above still apply.