Debian Samba vulnerabilities
192 known vulnerabilities affecting debian/samba.
Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27
Vulnerabilities
Page 9 of 10
CVE-2010-0787P4MEDIUMCVSS 4.4fixed in samba 2:3.4.5~dfsg-2 (bookworm)2010
CVE-2010-0787 [MEDIUM] CVE-2010-0787: samba - client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3....
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
Scope: local
bookworm: resolved (fixed in 2:3.4.5~dfsg-2)
bullseye: resolved (fixed in 2:3.4.5~dfsg-2)
forky: resolved (fixed
debian
CVE-2023-0225P4MEDIUMCVSS 4.3fixed in samba 2:4.17.7+dfsg-1 (bookworm)2023
CVE-2023-0225 [MEDIUM] CVE-2023-0225: samba - A flaw was found in Samba. An incomplete access check on dnsHostName allows auth...
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
Scope: local
bookworm: resolved (fixed in 2:4.17.7+dfsg-1)
bullseye: open
forky: resolved (fixed in 2:4.17.7+dfsg-1)
sid: resolved (fixed in 2:4.17.7+dfsg-1)
trixie: resolved (fixed in 2:4
debian
CVE-2010-1642P4LOWCVSS 5.0fixed in samba 2:3.5.4~dfsg-2 (bookworm)2010
CVE-2010-1642 [MEDIUM] CVE-2010-1642: samba - The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before...
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.
Scope: local
bookworm: resolved (fixed in 2:3.5.4~dfsg-2)
bullseye: resolved (fixed in
debian
CVE-2012-0817P4LOWCVSS 5.0fixed in samba 2:3.6.3-1 (bookworm)2012
CVE-2012-0817 [MEDIUM] CVE-2012-0817: samba - Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause...
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
Scope: local
bookworm: resolved (fixed in 2:3.6.3-1)
bullseye: resolved (fixed in 2:3.6.3-1)
forky: resolved (fixed in 2:3.6.3-1)
sid: resolved (fixed in 2:3.6.3-1)
trixie: resolved (fixed in 2:3.6.3-1)
debian
CVE-2022-1615P4MEDIUMCVSS 5.5fixed in samba 2:4.16.5+dfsg-2 (bookworm)2022
CVE-2022-1615 [MEDIUM] CVE-2022-1615: samba - In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
Scope: local
bookworm: resolved (fixed in 2:4.16.5+dfsg-2)
bullseye: open
forky: resolved (fixed in 2:4.16.5+dfsg-2)
sid: resolved (fixed in 2:4.16.5+dfsg-2)
trixie: resolved (fixed in 2:4.16.5+dfsg-2)
debian
CVE-2018-16852P4MEDIUMCVSS 6.5fixed in samba 2:4.9.2+dfsg-2 (bookworm)2018
CVE-2018-16852 [MEDIUM] CVE-2018-16852: samba - Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointe...
Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or DSPROPERTY_ZONE_SCAVENGING_SERVERS property is set, the server will follow a NULL pointe
debian
CVE-2025-9640P4MEDIUMCVSS 4.3fixed in samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)2025
CVE-2025-9640 [MEDIUM] CVE-2025-9640: samba - A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized ...
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
Scope: local
bookworm: resolved (fixed in 2:4.17.12+dfsg-0+deb12u3)
bullseye: r
debian
CVE-2004-0686P4MEDIUMCVSS 5.0fixed in samba 3.0.5 (bookworm)2004
CVE-2004-0686 [MEDIUM] CVE-2004-0686: samba - Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling ...
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
Scope: local
bookworm: resolved (fixed in 3.0.5)
bullseye: resolved (fixed in 3.0.5)
forky: resolved (fixed in 3.0.5)
sid: resolved (fixed in 3.0.5)
trixie: resolved (fixed in 3.0.5)
debian
CVE-2020-14323P4MEDIUMCVSS 5.5fixed in samba 2:4.13.2+dfsg-2 (bookworm)2020
CVE-2020-14323 [MEDIUM] CVE-2020-14323: samba - A null pointer dereference flaw was found in samba's Winbind service in versions...
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
Scope: local
bookworm: resolved (fixed in 2:4.13.2+dfsg-2)
bullseye: resolved (fixed in 2:4.13.2+dfsg-2)
forky: resolved (fixed in 2:4.13.2+dfsg-2)
s
debian
CVE-2013-0454P4MEDIUMCVSS 4.0fixed in samba 2:3.6.6-1 (bookworm)2013
CVE-2013-0454 [MEDIUM] CVE-2013-0454: samba - The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize...
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, o
debian
CVE-2004-0808P4MEDIUMCVSS 5.0fixed in samba 3.0.7 (bookworm)2004
CVE-2004-0808 [MEDIUM] CVE-2004-0808: samba - The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier...
The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.
Scope: local
bookworm: resolved (fixed in 3.0.7)
bullseye: resolved (fixed in 3.0.7)
forky
debian
CVE-2004-0829P4MEDIUMCVSS 5.0fixed in samba 2.2.11 (bookworm)2004
CVE-2004-0829 [MEDIUM] CVE-2004-0829: samba - smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service...
smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.
Scope: local
bookworm: resolved (fixed in 2.2.11)
bullseye: resolved (fixed in 2.2.11)
forky: resolved (fixed in 2.2.11)
sid: r
debian
CVE-2014-0178P4LOWCVSS 3.5fixed in samba 2:4.1.8+dfsg-1 (bookworm)2014
CVE-2014-0178 [LOW] CVE-2014-0178: samba - Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a ...
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHO
debian
CVE-2004-0807P4MEDIUMCVSS 5.0fixed in samba 3.0.7 (bookworm)2004
CVE-2004-0807 [MEDIUM] CVE-2004-0807: samba - Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (in...
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
Scope: local
bookworm: resolved (fixed in 3.0.7)
bullseye: resolved (fixed in 3.0.7)
forky: resolved (fixed in 3.0.7)
sid: resolved (fixed in 3.0.7)
trixie:
debian
CVE-2004-0930P4MEDIUMCVSS 5.0fixed in samba 3.0.8-1 (bookworm)2004
CVE-2004-0930 [MEDIUM] CVE-2004-0930: samba - The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions all...
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: resolved (fixed in 3.0.8-1)
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed
debian
CVE-2014-3493P4LOWCVSS 2.7fixed in samba 2:4.1.9+dfsg-1 (bookworm)2014
CVE-2014-3493 [LOW] CVE-2014-3493: samba - The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.1...
The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference
debian
CVE-2009-2906P4LOWCVSS 4.0fixed in samba 2:3.4.2-1 (bookworm)2009
CVE-2009-2906 [MEDIUM] CVE-2009-2906: samba - smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 be...
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
Scope: local
bookworm: resolved (fixed in 2:3.4.2-1)
bullseye: resolved (fixed in 2:3.4.2-1)
forky: resolved (fixed in 2:3.4.2-1)
sid: reso
debian
CVE-2004-2546P4MEDIUMCVSS 6.4fixed in samba 3.0.6-1 (bookworm)2004
CVE-2004-2546 [MEDIUM] CVE-2004-2546: samba - Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of...
Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).
Scope: local
bookworm: resolved (fixed in 3.0.6-1)
bullseye: resolved (fixed in 3.0.6-1)
forky: resolved (fixed in 3.0.6-1)
sid: resolved (fixed in 3.0.6-1)
trixie: resolved (fixed in 3.0.6-1)
debian
CVE-2011-2694P4LOWCVSS 2.6fixed in samba 2:3.5.10~dfsg-1 (bookworm)2011
CVE-2011-2694 [LOW] CVE-2011-2694: samba - Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat....
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Scope: local
bookworm: resolved (fixed
debian
CVE-2007-4138P4MEDIUMCVSS 6.9fixed in samba 3.0.26-1 (bookworm)2007
CVE-2007-4138 [MEDIUM] CVE-2007-4138: samba - The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0...
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
Scope: local
bookworm: resolved (fixed in 3.0.26-1)
bullseye: resolve
debian