VYPR

Vendor CVEs

Samba (software)

All CVEs

235 total · sorted by risk
  • CVE-2014-3493Jun 23, 2014
    risk 0.01cvss epss 0.07

    The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of…

  • CVE-2013-4496Mar 14, 2014
    risk 0.01cvss epss 0.11

    Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

  • CVE-2013-4475Nov 13, 2013
    risk 0.01cvss epss 0.09

    Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate…

  • CVE-2012-0870Feb 23, 2012
    risk 0.01cvss epss 0.07

    Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a…

  • CVE-2011-2694Jul 29, 2011
    risk 0.01cvss epss 0.06

    Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd…

  • CVE-2010-3069Sep 15, 2010
    risk 0.01cvss epss 0.11

    Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.

  • CVE-2007-5398Nov 16, 2007
    risk 0.01cvss epss 0.11

    Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name…

  • CVE-2007-0454Feb 6, 2007
    risk 0.01cvss epss 0.06

    Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

  • CVE-2004-0882Jan 27, 2005
    risk 0.01cvss epss 0.14

    Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.

  • CVE-2004-1154Jan 10, 2005
    risk 0.01cvss epss 0.13

    Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a…

  • CVE-2002-2196Dec 31, 2002
    risk 0.01cvss epss 0.07

    Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.

  • CVE-2025-0620Jun 6, 2025
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

  • CVE-2023-4154Nov 7, 2023
    risk 0.00cvss epss 0.01

    A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes,…

  • CVE-2023-42669Nov 6, 2023
    risk 0.00cvss epss 0.02

    A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with…

  • CVE-2023-3961Nov 3, 2023
    risk 0.00cvss epss 0.02

    A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS,…

  • CVE-2023-42670Nov 3, 2023
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for…

  • CVE-2023-4091Nov 3, 2023
    risk 0.00cvss epss 0.01

    A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client…

  • CVE-2023-34968Jul 20, 2023
    risk 0.00cvss epss 0.01

    A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC…

  • CVE-2023-3347Jul 20, 2023
    risk 0.00cvss epss 0.00

    A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to…

  • CVE-2022-2127Jul 20, 2023
    risk 0.00cvss epss 0.02

    An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to…

  • CVE-2023-0614Apr 3, 2023
    risk 0.00cvss epss 0.01

    The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

  • CVE-2023-0225Apr 3, 2023
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.

  • CVE-2023-0922Apr 3, 2023
    risk 0.00cvss epss 0.00

    The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

  • CVE-2022-45141Mar 6, 2023
    risk 0.00cvss epss 0.00

    Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting…

  • CVE-2021-20251Mar 6, 2023
    risk 0.00cvss epss 0.01

    A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

  • CVE-2022-41620Feb 8, 2023
    risk 0.00cvss epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

  • CVE-2018-14628Jan 17, 2023
    risk 0.00cvss epss 0.01

    An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

  • CVE-2022-3437Jan 12, 2023
    risk 0.00cvss epss 0.04

    A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory…

  • CVE-2022-3592Jan 12, 2023
    risk 0.00cvss epss 0.02

    A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS…

  • CVE-2022-32743Sep 1, 2022
    risk 0.00cvss epss 0.01

    Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

  • CVE-2022-1615Sep 1, 2022
    risk 0.00cvss epss 0.00

    In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.

  • CVE-2022-0336Aug 29, 2022
    risk 0.00cvss epss 0.01

    The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on…

  • CVE-2022-32742Aug 25, 2022
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot…

  • CVE-2022-32745Aug 25, 2022
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.

  • CVE-2022-32746Aug 25, 2022
    risk 0.00cvss epss 0.01

    A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as…

  • CVE-2022-32744Aug 25, 2022
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.

  • CVE-2022-2031Aug 25, 2022
    risk 0.00cvss epss 0.01

    A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use…

  • CVE-2021-3670Aug 23, 2022
    risk 0.00cvss epss 0.02

    MaxQueryDuration not honoured in Samba AD DC LDAP

  • CVE-2021-20316Aug 23, 2022
    risk 0.00cvss epss 0.01

    A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.

  • CVE-2020-25721Mar 16, 2022
    risk 0.00cvss epss 0.02

    Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.

  • CVE-2021-23192Mar 2, 2022
    risk 0.00cvss epss 0.02

    A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

  • CVE-2021-44141Feb 21, 2022
    risk 0.00cvss epss 0.01

    All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for…

  • CVE-2020-25717Feb 18, 2022
    risk 0.00cvss epss 0.02

    A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.

  • CVE-2016-2124Feb 18, 2022
    risk 0.00cvss epss 0.02

    A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

  • CVE-2020-25722Feb 18, 2022
    risk 0.00cvss epss 0.02

    Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.

  • CVE-2020-25718Feb 18, 2022
    risk 0.00cvss epss 0.02

    A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.

  • CVE-2020-25719Feb 18, 2022
    risk 0.00cvss epss 0.02

    A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found…

  • CVE-2021-43566Jan 11, 2022
    risk 0.00cvss epss 0.00

    All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available…

  • CVE-2021-3671Oct 12, 2021
    risk 0.00cvss epss 0.02

    A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.

  • CVE-2021-20277May 12, 2021
    risk 0.00cvss epss 0.04

    A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.