samba
Latest CVEs
The 15 most recently published vulnerabilities affecting samba.
- CVE-2026-4408Samba: remote code execution in samr9.0
- CVE-2026-1933Samba: missing access check on reparse point operations7.1
- CVE-2026-2340Samba: vfs_worm does not block directory modification6.5
- CVE-2026-3012Samba: group policy certificate enrollment uses http:// without validation8.0
- CVE-2026-4480Samba: samba: remote code execution in printing subsystem via unescaped job description9.0
- CVE-2026-29518Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write7.0
- CVE-2026-43617Rsync < 3.4.3 Authorization Bypass via Hostname Resolution4.8
- CVE-2026-43618Rsync < 3.4.3 Integer Overflow Information Disclosure8.1
- CVE-2026-43619Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls6.3
- CVE-2026-43620Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()6.5
- CVE-2026-45232Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy3.1
- CVE-2026-41035In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux...7.4
- CVE-2025-0620Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session4.9
- CVE-2024-58250The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.9.3
- CVE-2024-12084Rsync: heap buffer overflow in rsync due to improper checksum length handling9.8