CRITICAL10.0CVE-2025-10230A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without prope… from 0
CRITICAL9.8CVE-2022-44640Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distri… from 0
HIGH7.5A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller.
from 0
HIGH7.5A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all a…
from 0
HIGH7.5An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight.
from 0, < 2:4.13.13+dfsg-1~deb11u6
HIGH7.5samba - security update
from 0, < 2:4.4.5+dfsg-1
HIGH7.5samba - security update
from 0, < 2:4.2.14+dfsg-0+deb8u2
HIGH7.5The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle D…
from 0, < 2:4.3.7+dfsg-1
HIGH7.5The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4…
from 0, < 2:4.1.22+dfsg-1
HIGH7.5The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory alloc…
from 0, < 2:4.1.22+dfsg-1
HIGH7.5ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string…
from 0, < 2:4.1.22+dfsg-1
HIGH7.4Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-i…
from 0, < 2:4.3.7+dfsg-1
HIGH7.2samba - security update
from 0, < 2:4.1.22+dfsg-1
HIGH7.2samba - security update
from 0, < 2:3.5.6~dfsg-3squeeze13
MEDIUM6.8A flaw was found in the way Samba handled file/directory metadata.
from 0
MEDIUM6.5A heap-based Buffer Overflow flaw was discovered in Samba.
from 0, < 2:4.19.2+dfsg-1
MEDIUM6.5The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an atta…
from 0
MEDIUM6.5ldb - security update
from 0, < 2:4.9.5+dfsg-1
MEDIUM6.5samba - security update
from 0, < 2:4.5.6+dfsg-1
MEDIUM6.5samba - security update
from 0, < 2:4.2.14+dfsg-0+deb8u12
MEDIUM6.5samba - security update
from 0, < 2:4.3.6+dfsg-1
MEDIUM6.5samba - security update
from 0, < 2:3.6.6-6+deb7u7
MEDIUM6.3The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured…
from 0, < 2:4.3.7+dfsg-1
MEDIUM6.1A flaw was found in samba's pam_winbind.
from 0
MEDIUM6.1A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2.
from 0, < 2:4.9.5+dfsg-3
MEDIUM5.9A vulnerability was found in Samba's SMB2 packet signing mechanism.
from 0, < 2:4.17.10+dfsg-0+deb12u1
MEDIUM5.9samba - security update
from 0, < 2:4.13.13+dfsg-1~deb11u6
MEDIUM5.9samba - security update
from 0, < 2:4.17.10+dfsg-0+deb12u1
MEDIUM5.9samba - security update
from 0, < 2:4.13.13+dfsg-1~deb11u6
MEDIUM5.9The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed…
from 0
MEDIUM5.9A flaw was found in samba.
from 0
MEDIUM5.9Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of p…
from 0, < 2:4.9.2+dfsg-2
MEDIUM5.9Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn…
from 0, < 2:4.3.7+dfsg-1
MEDIUM5.9The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server sign…
from 0, < 2:4.3.7+dfsg-1
MEDIUM5.9The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "clie…
from 0, < 2:4.3.7+dfsg-1
MEDIUM5.9The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-…
from 0, < 2:4.3.7+dfsg-1
MEDIUM5.9samba - security update
from 0, < 2:4.3.7+dfsg-1
MEDIUM5.9samba - security update
from 0, < 2:3.6.6-6+deb7u9
MEDIUM5.9The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is con…
from 0, < 2:4.3.6+dfsg-1
MEDIUM5.4Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which all…
from 0, < 2:4.1.22+dfsg-1
MEDIUM5.3A path disclosure vulnerability was found in Samba.
from 0, < 2:4.13.13+dfsg-1~deb11u6
MEDIUM5.3A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight.
from 0, < 2:4.13.13+dfsg-1~deb11u6
MEDIUM5.3The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.…
from 0, < 2:4.1.22+dfsg-1
MEDIUM5.3samba - security update
from 0, < 2:4.1.22+dfsg-1
MEDIUM5.3samba - security update
from 0, < 2:3.6.6-6+deb7u6
MEDIUM4.7Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mo…
from 0, < 2:3.4.7~dfsg-2
MEDIUM4.4Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference.
from 0, < 2:4.9.2+dfsg-2
MEDIUM4.3samba - security update
from 0, < 2:4.13.13+dfsg-1~deb11u7
MEDIUM4.3samba - security update
from 0, < 2:4.13.13+dfsg-1~deb11u7
MEDIUM4.3All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exist…
from 0
LOW2.5All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in…
from 0, < 2:4.13.13+dfsg-1~deb11u4
—samba - security update
from 0, < 2:4.1.17+dfsg-1
—samba - security update
from 0, < 2:3.5.6~dfsg-3squeeze12
—samba - security update
from 0, < 2:3.6.6-6+deb7u5
—Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured,…
from 0, < 2:4.1.17+dfsg-1
—NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code…
from 0, < 2:4.1.11+dfsg-1
—The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users…
from 0, < 2:4.1.9+dfsg-1
—The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to caus…
from 0, < 2:4.1.9+dfsg-1
—The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before send…
from 0, < 2:4.1.8+dfsg-1
—samba - security update
from 0, < 2:4.1.8+dfsg-1
—samba - security update
from 0, < 2:3.6.6-6+deb7u4
—The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown…
from 0, < 2:4.1.6+dfsg-1
—Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all in…
from 0, < 2:4.1.6+dfsg-1
—samba - several
from 0, < 2:4.0.13+dfsg-1
—samba - several
from 0, < 2:3.5.6~dfsg-3squeeze11
—The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of gr…
from 0, < 2:4.0.13+dfsg-1
—Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key…
from 0, < 2:4.0.11+dfsg-1
—Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enable…
from 0, < 2:4.0.11+dfsg-1
—Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before…
from 0, < 2:3.6.17-1
—The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 an…
from 0, < 2:3.6.6-1
—Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12…
from 0, < 2:3.6.6-5
—samba - several issues
from 0, < 2:3.6.6-5
—samba - several issues
from 0, < 2:3.5.6~dfsg-3squeeze9
—samba - missing permission checks
from 0, < 2:3.6.5-1
—samba - missing permission checks
from 0, < 2:3.5.6~dfsg-3squeeze8
—samba - privilege escalation
from 0, < 2:3.6.4-1
—samba - privilege escalation
from 0, < 2:3.5.6~dfsg-3squeeze7
—Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before…
from 0, < 2:3.4.0~pre1-1
—Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making…
from 0, < 2:3.6.3-1
—The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) dev…
from 0, < 2:3.4.7~dfsg-2
—Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x…
from 0, < 2:3.5.10~dfsg-1
—samba - cross-side scripting
from 0, < 2:3.5.10~dfsg-1
—samba - cross-side scripting
from 0, < 2:3.2.5-4lenny15
—smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/m…
from 0, < 2:3.4.7~dfsg-2
—samba - missing input sanisiting
from 0, < 2:3.5.7~dfsg-1
—samba - missing input sanisiting
from 0, < 2:3.2.5-4lenny14
—samba - buffer overflow
from 0, < 2:3.5.5~dfsg-1
—samba - buffer overflow
from 0, < 2:3.2.5-4lenny13
—samba - arbitrary code execution
from 0, < 2:3.4.0~pre1-1
—samba - arbitrary code execution
from 0, < 2:3.2.5-4lenny12
—The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to tr…
from 0, < 2:3.5.4~dfsg-2
—The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of ser…
from 0, < 2:3.6.1-2
—The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allo…
from 0, < 2:3.4.6~dfsg-1
—smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote auth…
from 0, < 2:3.4.7~dfsg-1
—client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS shar…
from 0, < 2:3.4.5~dfsg-2
—samba - several vulnerabilities
from 0, < 2:3.4.5~dfsg-2
—samba - several vulnerabilities
from 0, < 2:3.2.5-4lenny9
—mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, do…
from 0, < 2:3.4.2-1
—smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a den…
from 0, < 2:3.4.2-1
—samba - several vulnerabilities
from 0, < 2:3.4.2-1