Vulnerabilities > Samba > Samba > 4.18.5

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-4154 Out-of-bounds Write vulnerability in Samba
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs).
network
low complexity
samba CWE-787
6.5
2023-11-06 CVE-2023-42669 A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements.
network
low complexity
samba redhat
6.5
2023-11-03 CVE-2023-3961 Path Traversal vulnerability in multiple products
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory.
network
low complexity
samba redhat fedoraproject CWE-22
critical
9.8
2023-11-03 CVE-2023-42670 A flaw was found in Samba.
network
low complexity
samba fedoraproject
6.5
2023-11-03 CVE-2023-4091 Incorrect Default Permissions vulnerability in multiple products
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes".
network
low complexity
samba fedoraproject redhat CWE-276
6.5
2023-10-25 CVE-2023-5568 Out-of-bounds Write vulnerability in Samba
A heap-based Buffer Overflow flaw was discovered in Samba.
network
low complexity
samba CWE-787
6.5
2023-03-06 CVE-2022-45141 Inadequate Encryption Strength vulnerability in Samba
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
network
low complexity
samba CWE-326
critical
9.8
2023-01-17 CVE-2018-14628 Missing Authorization vulnerability in multiple products
An information leak vulnerability was discovered in Samba's LDAP server.
network
low complexity
samba fedoraproject CWE-862
4.3
2022-11-09 CVE-2022-37966 Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
network
high complexity
microsoft fedoraproject netapp samba
8.1
2022-11-09 CVE-2022-37967 Windows Kerberos Elevation of Privilege Vulnerability
network
low complexity
microsoft fedoraproject netapp samba
7.2