VYPR

Vendor CVEs

Samba (software)

All CVEs

261 total · sorted by risk
  • CVE-2016-2110MedApr 25, 2016
    risk 0.39cvss 5.9epss 0.08

    The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove application-layer flags or…

  • CVE-2016-0771MedMar 13, 2016
    risk 0.39cvss 5.9epss 0.03

    The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from…

  • CVE-2025-2312MedMar 25, 2025
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos…

  • CVE-2023-5568MedOct 25, 2023
    risk 0.38cvss 5.9epss 0.02

    A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.

  • CVE-2023-3347MedJul 20, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to…

  • CVE-2023-0922MedApr 3, 2023
    risk 0.38cvss 5.9epss 0.00

    The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

  • CVE-2021-20251MedMar 6, 2023
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

  • CVE-2021-20316MedAug 23, 2022
    risk 0.37cvss 6.8epss 0.01

    A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.

  • CVE-2021-20254MedMay 5, 2021
    risk 0.37cvss 6.8epss 0.02

    A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added…

  • CVE-2022-1615MedSep 1, 2022
    risk 0.36cvss 5.5epss 0.00

    In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.

  • CVE-2020-14323MedOct 29, 2020
    risk 0.36cvss 5.5epss 0.01

    A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

  • CVE-2018-14629MedNov 28, 2018
    risk 0.36cvss 6.5epss 0.05

    A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

  • CVE-2016-2125MedOct 31, 2018
    risk 0.36cvss 6.5epss 0.09

    It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

  • CVE-2015-5299MedDec 29, 2015
    risk 0.36cvss 5.3epss 0.14

    The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by…

  • CVE-2015-5296MedDec 29, 2015
    risk 0.36cvss 5.4epss 0.07

    Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to…

  • CVE-2026-58218MedJul 30, 2026
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names,…

  • CVE-2026-2340MedMay 27, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with…

  • CVE-2026-43620MedMay 20, 2026
    risk 0.35cvss 6.5epss 0.00

    Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility…

  • CVE-2023-34968MedJul 20, 2023
    risk 0.35cvss 5.3epss 0.01

    A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC…

  • CVE-2022-41620MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

  • CVE-2022-32746MedAug 25, 2022
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as…

  • CVE-2020-10700MedMay 4, 2020
    risk 0.35cvss 5.3epss 0.02

    A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before…

  • CVE-2019-14902MedJan 21, 2020
    risk 0.35cvss 5.4epss 0.02

    There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

  • CVE-2019-14870MedDec 10, 2019
    risk 0.35cvss 5.4epss 0.03

    All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or…

  • CVE-2019-14861MedDec 10, 2019
    risk 0.35cvss 5.3epss 0.02

    All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In…

  • CVE-2019-14833MedNov 6, 2019
    risk 0.35cvss 5.4epss 0.02

    A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script…

  • CVE-2019-12436MedJun 19, 2019
    risk 0.35cvss 6.5epss 0.03

    Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

  • CVE-2019-3824MedMar 6, 2019
    risk 0.35cvss 6.5epss 0.03

    A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.

  • CVE-2015-3223MedDec 29, 2015
    risk 0.35cvss 5.3epss 0.07

    The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop)…

  • CVE-2026-58216MedJul 30, 2026
    risk 0.34cvss 5.3epss 0.01

    An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six…

  • CVE-2026-43619MedMay 20, 2026
    risk 0.34cvss 6.3epss 0.00

    Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported…

  • CVE-2018-10918MedAug 22, 2018
    risk 0.34cvss 5.2epss 0.03

    A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4…

  • CVE-2021-20208MedApr 19, 2021
    risk 0.33cvss 6.1epss 0.01

    A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

  • CVE-2019-14847MedNov 6, 2019
    risk 0.32cvss 4.9epss 0.02

    A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

  • CVE-2022-2127MedJul 20, 2023
    risk 0.31cvss 5.9epss 0.02

    An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to…

  • CVE-2016-2124MedFeb 18, 2022
    risk 0.31cvss 5.9epss 0.02

    A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

  • CVE-2011-3585MedDec 31, 2019
    risk 0.31cvss 4.7epss 0.00

    Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.

  • CVE-2020-14342MedSep 9, 2020
    risk 0.29cvss 4.4epss 0.01

    It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their…

  • CVE-2023-0225MedApr 3, 2023
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.

  • CVE-2022-32742MedAug 25, 2022
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot…

  • CVE-2021-44141MedFeb 21, 2022
    risk 0.28cvss 4.3epss 0.01

    All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for…

  • CVE-2020-14318MedDec 3, 2020
    risk 0.28cvss 4.3epss 0.02

    A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

  • CVE-2019-3880MedApr 9, 2019
    risk 0.28cvss 5.4epss 0.03

    A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba…

  • CVE-2018-10919MedAug 22, 2018
    risk 0.28cvss 4.3epss 0.02

    The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16,…

  • CVE-2018-1050MedMar 13, 2018
    risk 0.28cvss 4.3epss 0.07

    All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler…

  • CVE-2017-12163MedJul 26, 2018
    risk 0.27cvss 4.1epss 0.08

    An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the…

  • CVE-2025-0620MedJun 6, 2025
    risk 0.25cvss 4.9epss 0.01

    A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

  • CVE-2026-43617MedMay 20, 2026
    risk 0.24cvss 4.8epss 0.00

    Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP…

  • CVE-2017-17433LowDec 6, 2017
    risk 0.24cvss 3.7epss 0.02

    The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended…

  • CVE-2025-9640MedOct 15, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure…

Page 3 of 6