Skip to main content

Vendor archive

samba CVEs

Beta · best-effort

245 CVEs tagged to vendor samba29 Critical, 75 High, 120 Medium, 21 Low, 0 Unrated.

CVE-2023-0922

Published Apr 3, 2023

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0614

Published Apr 3, 2023

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0225

Published Apr 3, 2023

A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the director…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45141

Published Mar 6, 2023

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable S…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-20251

Published Mar 6, 2023

A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14628

Published Jan 17, 2023

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3592

Published Jan 12, 2023

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote use…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3437

Published Jan 12, 2023

A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44640

Published Dec 25, 2022

Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-4603

Published Dec 18, 2022

A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0336

Published Aug 29, 2022

The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-32746

Published Aug 25, 2022

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32745

Published Aug 25, 2022

A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32744

Published Aug 25, 2022

A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32742

Published Aug 25, 2022

A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory content…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 245 CVEsPage 2 of 10