Vulnerabilities > Samba > Samba > 4.0.15

DATE CVE VULNERABILITY TITLE RISK
2023-04-03 CVE-2023-0614 Cleartext Storage of Sensitive Information vulnerability in Samba
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
network
low complexity
samba CWE-312
6.5
2023-01-17 CVE-2018-14628 Missing Authorization vulnerability in multiple products
An information leak vulnerability was discovered in Samba's LDAP server.
network
low complexity
samba fedoraproject CWE-862
4.3
2023-01-12 CVE-2022-3437 Heap-based Buffer Overflow vulnerability in multiple products
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal.
network
low complexity
samba fedoraproject CWE-122
6.5
2022-12-25 CVE-2022-42898 Integer Overflow or Wraparound vulnerability in multiple products
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms.
network
low complexity
mit heimdal-project samba CWE-190
8.8
2022-08-29 CVE-2022-0336 Incorrect Default Permissions vulnerability in multiple products
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database.
network
low complexity
samba fedoraproject CWE-276
8.8
2022-08-25 CVE-2022-2031 Improper Authentication vulnerability in Samba
A flaw was found in Samba.
network
low complexity
samba CWE-287
8.8
2022-08-25 CVE-2022-32742 Unspecified vulnerability in Samba
A flaw was found in Samba.
network
low complexity
samba
4.3
2022-08-23 CVE-2021-20316 Race Condition vulnerability in multiple products
A flaw was found in the way Samba handled file/directory metadata.
network
high complexity
samba debian redhat CWE-362
6.8
2022-03-02 CVE-2021-3738 Use After Free vulnerability in Samba
In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'.
network
low complexity
samba CWE-416
8.8
2022-02-21 CVE-2021-44141 Link Following vulnerability in multiple products
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition.
network
low complexity
samba redhat fedoraproject CWE-59
4.3