samba
36 known vulnerabilities affecting samba products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-4480 | Medium | 13.9% | 9.0 | A flaw was found in the Samba printing subsystem. Samba passes the client-contro… | |
| CVE-2024-12085 | Medium | 8.8% | 7.5 | A flaw was found in rsync which could be triggered when rsync compares file chec… | |
| CVE-2022-37967 | Medium | 4.1% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2022-37966 | Medium | 2.5% | 8.1 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | |
| CVE-2026-4408 | Medium | 2.5% | 9.0 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S… | |
| CVE-2022-38023 | Medium | 2.4% | 8.1 | Netlogon RPC Elevation of Privilege Vulnerability | |
| CVE-2026-1933 | Medium | 0.9% | 7.1 | A flaw was found in Samba’s handling of NTFS-style reparse points on shares conf… | |
| CVE-2026-43618 | Medium | 0.8% | 8.1 | Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the c… | |
| CVE-2026-70461 | Medium | 0.6% | 8.2 | rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that … | |
| CVE-2026-70455 | Medium | 0.6% | 7.5 | rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows … | |
| CVE-2026-53791 | Medium | 0.5% | 9.1 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that all… | |
| CVE-2026-53795 | Medium | 0.4% | 8.1 | rsync before 3.5.0 contains an arbitrary file write vulnerability that allows at… | |
| CVE-2026-41035 | Medium | 0.4% | 7.4 | In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value … | |
| CVE-2026-70463 | Medium | 0.4% | 8.1 | rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directiv… | |
| CVE-2026-3012 | Medium | 0.3% | 8.0 | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. W… | |
| CVE-2026-53784 | Medium | 0.2% | 7.1 | rsync before 3.5.0 contains a path traversal vulnerability that allows remote cl… | |
| CVE-2026-53802 | Medium | 0.2% | 7.1 | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows att… | |
| CVE-2026-53803 | Medium | 0.2% | 7.8 | rsync before 3.5.0 contains a symlink following vulnerability that allows local … | |
| CVE-2026-29518 | Medium | 0.2% | 7.0 | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race… | |
| CVE-2024-12086 | Low | 1.8% | 6.1 | A flaw was found in rsync. It could allow a server to enumerate the contents of … | |
| CVE-2026-2340 | Low | 0.9% | 6.5 | A flaw was found in Samba’s vfs_worm module. The module is intended to provide w… | |
| CVE-2025-0620 | Low | 0.7% | 4.9 | A flaw was found in Samba. The smbd service daemon does not pick up group member… | |
| CVE-2026-70459 | Low | 0.4% | 5.3 | rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in th… | |
| CVE-2026-43620 | Low | 0.4% | 6.5 | Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read v… | |
| CVE-2026-70457 | Low | 0.4% | 6.5 | rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() whe… | |
| CVE-2026-53789 | Low | 0.4% | 6.5 | rsync before 3.5.0 contains an improper path handling vulnerability that allows … | |
| CVE-2026-45232 | Low | 0.3% | 3.1 | Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vuln… | |
| CVE-2026-53786 | Low | 0.3% | 6.5 | rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authe… | |
| CVE-2026-53798 | Low | 0.3% | 5.3 | rsync before 3.5.0 contains a privilege confusion vulnerability in the name-conv… | |
| CVE-2026-58224 | Low | 0.3% | 6.5 | A flaw was found in Samba's CTDB, the clustered database service used by Samba. … | |
| CVE-2026-53801 | Low | 0.3% | 5.9 | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender… | |
| CVE-2026-43617 | Low | 0.3% | 4.8 | Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in t… | |
| CVE-2026-53797 | Low | 0.1% | 4.7 | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender… | |
| CVE-2026-53800 | Low | 0.1% | 4.7 | rsync before 3.5.0 contains a symlink race condition vulnerability in the --remo… | |
| CVE-2026-53799 | Low | 0.1% | 6.3 | rsync before 3.5.0 contains a symlink race condition vulnerability that allows l… | |
| CVE-2026-43619 | Low | 0.1% | 6.3 | Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in … |