Samba / Samba
214 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-58224 | Samba: ctdb fails to do integrity checking of received packets | MEDIUM | 6.5 | Aug 14, 2026 |
| CVE-2026-4408 | Samba: remote code execution in samr | CRITICAL | 9.8 | May 28, 2026 |
| CVE-2026-1933 | Samba: missing access check on reparse point operations | HIGH | 7.1 | May 27, 2026 |
| CVE-2026-2340 | Samba: vfs_worm does not block directory modification | MEDIUM | 6.5 | May 27, 2026 |
| CVE-2026-3012 | Samba: group policy certificate enrollment uses http:// without validation | HIGH | 8.0 | May 27, 2026 |
| CVE-2026-4480 | Samba: samba: remote code execution in printing subsystem via unescaped job description | CRITICAL | 9.8 | May 26, 2026 |
| CVE-2025-0620 | Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session | MEDIUM | 4.9 | Jun 6, 2025 |
| CVE-2023-4154 | Samba: ad dc password exposure to privileged users and rodcs | HIGH | 7.5 | Nov 7, 2023 |
| CVE-2023-42669 | Samba: "rpcecho" development server allows denial of service via sleep() call on ad dc | MEDIUM | 6.5 | Nov 6, 2023 |
| CVE-2023-3961 | Samba: smbd allows client access to unix domain sockets on the file system as root | CRITICAL | 9.8 | Nov 3, 2023 |
| CVE-2023-42670 | Samba: ad dc busy rpc multiple listener dos | MEDIUM | 6.5 | Nov 3, 2023 |
| CVE-2023-4091 | Samba: smb clients can truncate files with read-only permissions | MEDIUM | 6.5 | Nov 3, 2023 |
| CVE-2023-5568 | Samba: heap buffer overflow with freshness tokens in the heimdal kdc | MEDIUM | 6.5 | Oct 24, 2023 |
| CVE-2023-34968 | Samba: spotlight server-side share path disclosure | MEDIUM | 5.3 | Jul 20, 2023 |
| CVE-2023-34967 | Samba: type confusion in mdssvc rpc service for spotlight | MEDIUM | 5.3 | Jul 20, 2023 |
| CVE-2023-34966 | Samba: infinite loop in mdssvc rpc service for spotlight | HIGH | 7.5 | Jul 20, 2023 |
| CVE-2023-3347 | Samba: smb2 packet signing is not enforced when "server signing = required" is set | MEDIUM | 5.9 | Jul 20, 2023 |
| CVE-2022-2127 | Samba: out-of-bounds read in winbind auth_crap | MEDIUM | 5.9 | Jul 20, 2023 |
| CVE-2023-0922 | samba: AD DC admin tool samba-tool sends passwords in cleartext | MEDIUM | 5.9 | Apr 3, 2023 |
| CVE-2023-0614 | samba: Access controlled AD LDAP attributes can be discovered | HIGH | 7.7 | Apr 3, 2023 |
| CVE-2023-0225 | samba: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users | MEDIUM | 4.3 | Apr 3, 2023 |
| CVE-2022-45141 | samba: Samba AD DC using Heimdal can be forced to issue rc4-hmac encrypted Kerberos tickets | CRITICAL | 9.8 | Mar 6, 2023 |
| CVE-2021-20251 | samba: Race condition in the bad password lockout code | MEDIUM | 5.9 | Mar 6, 2023 |
| CVE-2018-14628 | samba: Unprivileged read of deleted object tombstones in AD LDAP server | MEDIUM | 4.3 | Jan 17, 2023 |
| CVE-2022-3592 | samba: wide links protection broken | MEDIUM | 6.5 | Jan 12, 2023 |
Showing 1 to 25 of 214 CVEs