Skip to main content

Vendor archive

samba CVEs

Beta · best-effort

245 CVEs tagged to vendor samba29 Critical, 75 High, 120 Medium, 21 Low, 0 Unrated.

CVE-2026-29518

Published May 20, 2026

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended d…

CVSS 7.3 · High
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2026-45232

Published May 20, 2026

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-43620

Published May 20, 2026

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-43619

Published May 20, 2026

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, lin…

CVSS 7.2 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-43618

Published May 20, 2026

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malic…

CVSS 6.1 · Medium
evidence mentions
12
Buzz score
45.1
Vendor/product tagsBeta · best-effort

CVE-2026-43617

Published May 20, 2026

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attac…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-41035

Published Apr 16, 2026

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka -…

CVSS 7.4 · High
evidence mentions
30
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2025-0620

Published Jun 6, 2025

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until…

CVSS 4.9 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2024-12086

Published Jan 14, 2025

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a c…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-4154

Published Nov 7, 2023

A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RO…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42669

Published Nov 6, 2023

A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC funct…

CVSS 6.5 · Medium

CVE-2023-42670

Published Nov 3, 2023

A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5568

Published Oct 25, 2023

A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 245 CVEsPage 1 of 10