CVEs (215)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets. |
In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'. These handles can reference connections to our sam.ldb database. Howev...Show more |
A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing t...Show more |
3Fedoraproject RedhatSamba3Fedora SambaStorageJun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. S...Show more |
6Canonical DebianFedoraproject+3 more23Codeready Linux Builder Debian LinuxDiskstation Manager+20 moreJun 17, 2026 Feb 21, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSamba+1 moreJun 17, 2026 Feb 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise. |
5Canonical DebianFedoraproject+2 more17Debian Linux Enterprise LinuxEnterprise Linux Desktop+14 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictl...Show more |
2Fedoraproject Samba2Fedora SambaJun 17, 2026 Feb 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets. |
5Canonical DebianFedoraproject+2 more25Codeready Linux Builder Debian LinuxEnterprise Linux+22 moreJun 17, 2026 Feb 18, 2022 N/A· v4 8.1 HIGH· v3 8.5 HIGH· v2 A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
5Canonical DebianFedoraproject+2 more24Codeready Linux Builder Debian LinuxEnterprise Linux+21 moreNov 21, 2024 Feb 18, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note...Show more |
3Debian NetappSamba5Debian Linux Management Services For Element SoftwareManagement Services For Netapp Hci+2 moreJun 17, 2026 Oct 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. |
3Debian FedoraprojectSamba3Debian Linux FedoraSambaJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a...Show more |
3Debian FedoraprojectSamba3Debian Linux FedoraSambaJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest thr...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 5, 2021 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the arr...Show more |
2Redhat Samba3Enterprise Linux SambaStorageJun 17, 2026 Dec 3, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the att...Show more |
2Redhat Samba2Enterprise Linux SambaJun 17, 2026 Dec 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but...Show more |
2Microsoft Samba4Samba Windows Server 2012Windows Server 2016+1 moreJun 17, 2026 Nov 11, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service. |
8Canonical DebianFedoraproject+5 more15Debian Linux Directory ServerFedora+12 moreJun 17, 2026 Aug 17, 2020 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successful...Show more |