Samba
samba
246 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (246)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Samba2Debian Linux RsyncMay 13, 2026 Dec 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sa...Show more |
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data struc...Show more |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreMay 13, 2026 Nov 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory. |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreMay 13, 2026 Nov 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request. |
3Canonical DebianSamba3Debian Linux RsyncUbuntu LinuxMay 13, 2026 Nov 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer ove...Show more |
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the...Show more |
5Apple DebianFreebsd+2 more6Debian Linux FreebsdHeimdal+3 moreMay 13, 2026 Jul 13, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_tick...Show more |
3Debian RedhatSamba8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 6, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks. |
2Debian Samba2Debian Linux SambaApr 21, 2026 May 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to...Show more |
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to cr...Show more |
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 s...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying t...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB s...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive info...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perfo...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoi...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-se...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (a...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Apr 12, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-d...Show more |
The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-b...Show more |