cbcvebase.

Debian Samba vulnerabilities

192 known vulnerabilities affecting debian/samba.

Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27

Vulnerabilities

Page 1 of 10
CVE-2017-7494P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in samba 2:4.5.8+dfsg-2 (bookworm)2017
CVE-2017-7494 [CRITICAL] CVE-2017-7494: samba - Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to r... Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it. Scope: local bookworm: resolved (fixed in 2:4.5.8+dfsg-2) bullseye: resolved (fixed in 2:4.5.8+dfsg-2) forky: resolved (fixed
debian
CVE-2020-1472P1MEDIUMCVSS 5.5KEVPoCRansomwarefixed in samba 2:4.13.2+dfsg-2 (bookworm)2020
CVE-2020-1472 [MEDIUM] CVE-2020-1472: samba - An elevation of privilege vulnerability exists when an attacker establishes a vu... An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated
debian
CVE-2021-44142P1HIGHCVSS 8.8ExploitedPoCfixed in samba 2:4.16.0+dfsg-2 (bookworm)2021
CVE-2021-44142 [HIGH] CVE-2021-44142: samba - The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide ... The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker
debian
CVE-2003-0201P2CRITICALCVSS 10.0ExploitedPoCfixed in samba 3.0 (bookworm)2003
CVE-2003-0201 [CRITICAL] CVE-2003-0201: samba - Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x befo... Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code. Scope: local bookworm: resolved (fixed in 3.0) bullseye: resolved (fixed in 3.0) forky: resolved (fixed in 3.0) sid: resolved (fixed in 3.0) trixie: resolved (fixe
debian
CVE-2013-0213P2MEDIUMCVSS 5.1ExploitedRansomwarefixed in samba 2:3.6.6-5 (bookworm)2013
CVE-2013-0213 [MEDIUM] CVE-2013-0213: samba - The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x befor... The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element. Scope: local bookworm: resolved (fixed in 2:3.6.6-5) bullseye: resolved (fixed in 2:3.6.6-5) forky: resolved (fixed in 2:3.6.6-5) sid: resolved (fixed in 2:3.6.6-5)
debian
CVE-2015-0240P2CRITICALCVSS 10.0PoCfixed in samba 2:4.1.17+dfsg-1 (bookworm)2015
CVE-2015-0240 [CRITICAL] CVE-2015-0240: samba - The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.2... The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reac
debian
CVE-2012-1182P2CRITICALCVSS 10.0PoCfixed in samba 2:3.6.4-1 (bookworm)2012
CVE-2012-1182 [CRITICAL] CVE-2012-1182: samba - The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.... The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call. Scope: local bookworm: resolved (fixed in 2:3.6.4-1) bullseye: resolved (fixe
debian
CVE-2007-2446P2HIGHCVSS 10.0PoCfixed in samba 3.0.25-1 (bookworm)2007
CVE-2007-2446 [CRITICAL] CVE-2007-2446: samba - Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 t... Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5
debian
CVE-2008-1105P2MEDIUMCVSS 7.5PoCfixed in samba 1:3.0.30-1 (bookworm)2008
CVE-2008-1105 [HIGH] CVE-2008-1105: samba - Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Sam... Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response. Scope: local bookworm: resolved (fixed in 1:3.0.30-1) bullseye: resolved (fixed in 1:3.0.30-1) forky: resolved (fixed in 1:3.0.30-1) sid: resolved (fixed in 1:3.0.30-1) trixie: resolved (fix
debian
CVE-2010-2063P2HIGHCVSS 7.5PoCfixed in samba 2:3.4.0~pre1-1 (bookworm)2010
CVE-2010-2063 [HIGH] CVE-2010-2063: samba - Buffer overflow in the SMB1 packet chaining implementation in the chain_reply fu... Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet. Scope: local bookworm: resolved (fixed in 2:3.4.0~pre1-1) bullseye: resolved
debian
CVE-2003-0085P2CRITICALCVSS 10.0PoCfixed in samba 2.2.8 (bookworm)2003
CVE-2003-0085 [CRITICAL] CVE-2003-0085: samba - Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon ... Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code. Scope: local bookworm: resolved (fixed in 2.2.8) bullseye: resolved (fixed in 2.2.8) forky: resolved (fixed in 2.2.8) sid: resolved (fixed in 2.2.8) trixie: resolved (fixed in 2.2
debian
CVE-2007-6015P2HIGHCVSS 9.3PoCfixed in samba 3.0.28-1 (bookworm)2007
CVE-2007-6015 [CRITICAL] CVE-2007-6015: samba - Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0... Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request. Scope: local bookworm: resolved (fixed in 3.0.28-1) bulls
debian
CVE-2007-2447P2HIGHCVSS 6.0PoCfixed in samba 3.0.25-1 (bookworm)2007
CVE-2007-2447 [MEDIUM] CVE-2007-2447: samba - The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote ... The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in
debian
CVE-2025-10230P1CRITICALCVSS 10.0fixed in samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)2025
CVE-2025-10230 [CRITICAL] CVE-2025-10230: samba - A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names fr... A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated netw
debian
CVE-2004-0600P2CRITICALCVSS 10.0PoCfixed in samba 3.0.5 (bookworm)2004
CVE-2004-0600 [CRITICAL] CVE-2004-0600: samba - Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.... Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication. Scope: local bookworm: resolved (fixed in 3.0.5) bullseye: resolved (fixed in 3.0.5) forky: resolved (fixed in 3.0.5) sid: resolved (fixed in 3.0.5) trixie: resolved (
debian
CVE-2017-2619P2HIGHCVSS 7.5PoCfixed in samba 2:4.5.6+dfsg-2 (bookworm)2017
CVE-2017-2619 [HIGH] CVE-2017-2619: samba - Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious clie... Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition. Scope: local bookworm: resolved (fixed in 2:4.5.6+dfsg-2) bullseye: resolved (fixed in 2:4.5.6+dfsg-2) forky: resolved (fixed in 2:4.5.6+dfsg-2) sid: resolved (fixed in 2:4.5.6
debian
CVE-2009-1886P2CRITICALCVSS 9.3PoCfixed in samba 2:3.3.6-1 (bookworm)2009
CVE-2009-1886 [CRITICAL] CVE-2009-1886: samba - Multiple format string vulnerabilities in client/client.c in smbclient in Samba ... Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename. Scope: local bookworm: resolved (fixed in 2:3.3.6-1) bullseye: resolved (fixed in 2:3.3.6-1) forky: resolved (fixed in 2:3.3.6-1) sid: resolved (fixed in 2:3
debian
CVE-2002-1318P3CRITICALCVSS 10.0PoCfixed in samba 2.2.7 (bookworm)2002
CVE-2002-1318 [CRITICAL] CVE-2002-1318: samba - Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a ... Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string. Scope: local bookworm: resolved (fixed in 2.2.7) bullseye: resolved (fixed in 2.2
debian
CVE-2013-4124P3LOWCVSS 5.0PoCfixed in samba 2:3.6.17-1 (bookworm)2013
CVE-2013-4124 [MEDIUM] CVE-2013-4124: samba - Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Sa... Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet. Scope: local bookworm: resolved (fixed in 2:3.6.17-1) bullseye: resolved (fixed in 2:3.6.17-1) forky: resolved (fixed in 2:3.6.
debian
CVE-2014-3560P2HIGHCVSS 7.9fixed in samba 2:4.1.11+dfsg-1 (bookworm)2014
CVE-2014-3560 [HIGH] CVE-2014-3560: samba - NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x befor... NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h. Scope: local bookworm: resolved (fixed in 2:4.1.11+dfsg-1) bullseye: resolved (fixed i
debian
1 / 10Next →
Debian Samba vulnerabilities | cvebase