VYPR

Winbind

by Samba (software)

CVEs (3)

  • CVE-2026-15779MedJul 15, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for…

  • CVE-2020-14323MedOct 29, 2020
    risk 0.36cvss 5.5epss 0.01

    A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

  • CVE-2007-4138Sep 14, 2007
    risk 0.00cvss epss 0.01

    The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group…