Vendor CVEs
Samba (software)
All CVEs
262 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-0082 | 0.00 | — | 0.04 | Mar 3, 2004 | The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password. | |||
| CVE-2004-0028 | 0.00 | — | 0.02 | Feb 3, 2004 | jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands. | |||
| CVE-2003-1332 | 0.00 | — | 0.05 | Dec 31, 2003 | Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201. | |||
| CVE-2003-0086 | 0.00 | — | 0.01 | Mar 31, 2003 | The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown. | |||
| CVE-2002-0080 | 0.00 | — | 0.01 | Mar 15, 2002 | rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed. | |||
| CVE-2000-0938 | 0.00 | — | 0.02 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server. | |||
| CVE-2000-0939 | 0.00 | — | 0.02 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart. | |||
| CVE-1999-0812 | 0.00 | — | 0.01 | Jul 12, 2000 | Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations. | |||
| CVE-1999-0810 | 0.00 | — | 0.02 | Jul 21, 1999 | Denial of service in Samba NETBIOS name service daemon (nmbd). | |||
| CVE-1999-1288 | 0.00 | — | 0.00 | Nov 19, 1998 | Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program. | |||
| CVE-2026-58221 | 0.00 | — | — | — | Several security issues were fixed in Samba. | |||
| CVE-2026-6949 | 0.00 | — | — | — | Several security issues were fixed in Samba. |
- CVE-2004-0082Mar 3, 2004risk 0.00cvss —epss 0.04
The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.
- CVE-2004-0028Feb 3, 2004risk 0.00cvss —epss 0.02
jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.
- CVE-2003-1332Dec 31, 2003risk 0.00cvss —epss 0.05
Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.
- CVE-2003-0086Mar 31, 2003risk 0.00cvss —epss 0.01
The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.
- CVE-2002-0080Mar 15, 2002risk 0.00cvss —epss 0.01
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
- CVE-2000-0938Dec 19, 2000risk 0.00cvss —epss 0.02
Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
- CVE-2000-0939Dec 19, 2000risk 0.00cvss —epss 0.02
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.
- CVE-1999-0812Jul 12, 2000risk 0.00cvss —epss 0.01
Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.
- CVE-1999-0810Jul 21, 1999risk 0.00cvss —epss 0.02
Denial of service in Samba NETBIOS name service daemon (nmbd).
- CVE-1999-1288Nov 19, 1998risk 0.00cvss —epss 0.00
Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.
- risk 0.00cvss —epss —
Several security issues were fixed in Samba.
- risk 0.00cvss —epss —
Several security issues were fixed in Samba.
Page 6 of 6