CVE-2025-0620
- EPSS 0.1%
- Published 06.06.2025 13:10:07
- Last modified 13.08.2025 15:12:08
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
CVE-2020-25720
- EPSS 0.22%
- Published 17.11.2024 11:15:04
- Last modified 18.11.2024 17:11:17
A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creatio...
CVE-2023-4154
- EPSS 0.31%
- Published 07.11.2023 20:15:08
- Last modified 21.11.2024 08:34:29
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right...
CVE-2023-42669
- EPSS 0.58%
- Published 06.11.2023 07:15:09
- Last modified 21.11.2024 08:22:55
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpc...
CVE-2023-3961
- EPSS 1.94%
- Published 03.11.2023 13:15:08
- Last modified 21.11.2024 08:18:24
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services ...
CVE-2023-4091
- EPSS 0.48%
- Published 03.11.2023 08:15:08
- Last modified 21.11.2024 08:34:22
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows openi...
CVE-2023-42670
- EPSS 0.49%
- Published 03.11.2023 08:15:07
- Last modified 21.11.2024 08:22:55
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intende...
CVE-2023-5568
- EPSS 4.71%
- Published 25.10.2023 18:17:43
- Last modified 21.11.2024 08:42:02
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
CVE-2022-2127
- EPSS 1.25%
- Published 20.07.2023 15:15:11
- Last modified 21.11.2024 07:00:22
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable ...
CVE-2023-34966
- EPSS 15.9%
- Published 20.07.2023 15:15:11
- Last modified 21.11.2024 08:07:44
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that c...