Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect … Rsync 3.4.3+ Fix from $1,9502026-05-20 HIGH 8.1 CVE-2026-43618 Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked … Rsync after 3.4.2 Fix from $1,9502026-05-20 MEDIUM 6.3 CVE-2026-43619 Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unli… Rsync after 3.4.2 Fix from $1,6002026-05-20 MEDIUM 5.5 CVE-2026-43620 Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rs… Rsync after 3.4.2 Fix from $1,6002026-05-20 HIGH 7.8 CVE-2026-41035 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim… Rsync after 3.4.1 Fix from $1,9502026-04-16 MEDIUM 6.5 CVE-2023-4154 A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Re… Samba 4.17.12 / 4.18.8+ Fix from $1,6002023-11-07 MEDIUM 6.5 CVE-2023-5568 A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a d… Samba 4.19.2+ Fix from $1,6002023-10-25 MEDIUM 5.9 CVE-2023-0922 The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conn… Samba 4.16.10 / 4.17.7+ Fix from $1,6002023-04-03 MEDIUM 6.5 CVE-2023-0614 The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may b… Samba 4.16.10 / 4.17.7+ Fix from $1,6002023-04-03 CRITICAL 9.8 CVE-2022-45141 Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that … Samba 4.15.13 / 4.16.8+ Fix from $2,3002023-03-06 MEDIUM 6.5 CVE-2022-4603 A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppd… Ppp 2.5.0+ Fix from $1,6002022-12-18 HIGH 8.8 CVE-2022-32744 A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own ke… Samba 4.14.14 / 4.15.9+ Fix from $1,9502022-08-25 HIGH 8.1 CVE-2022-32745 A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting… Samba 4.14.14 / 4.15.9+ Fix from $1,9502022-08-25 MEDIUM 5.4 CVE-2022-32746 A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database mo… Samba 4.14.14 / 4.15.9+ Fix from $1,6002022-08-25 HIGH 8.8 CVE-2022-2031 A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them t… Samba 4.14.14 / 4.15.9+ Fix from $1,9502022-08-25 HIGH 8.8 CVE-2020-25721 Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a … Samba 4.13.14 / 4.14.10+ Fix from $1,9502022-03-16 HIGH 8.8 CVE-2021-3738 In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'.… Samba 4.13.14 / 4.14.10+ Fix from $1,9502022-03-02 HIGH 7.5 CVE-2021-23192 A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an … Samba 4.13.14 / 4.14.10+ Fix from $1,9502022-03-02 HIGH 7.4 CVE-2020-14387 A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthentic… Rsync 3.2.4+ Fix from $1,9502021-05-27 HIGH 7.5 CVE-2018-16860 A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, exclud… Samba 4.8.12 / 4.9.8+ Fix from $1,9502019-07-31 MEDIUM 6.5 CVE-2019-12435 Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS mana… Samba 4.9.9 / 4.10.5+ Fix from $1,6002019-06-19 MEDIUM 5.9 CVE-2018-16853 Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerb… Samba 4.7.12 / 4.8.7+ Fix from $1,6002018-11-28 MEDIUM 5.9 CVE-2018-16857 Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) … Samba 4.9.3+ Fix from $1,6002018-11-28 HIGH 8.8 CVE-2016-2123EPSS 6% A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-cont… Samba 4.3.13 / 4.4.8+ Fix from $1,9502018-11-01 MEDIUM 6.5 CVE-2018-1140EPSS 11% A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause … Samba 4.8.4+ Fix from $1,6002018-08-22 CRITICAL 9.8 CVE-2017-15994 rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrict… Rsync after 3.1.2 Fix from $2,3002017-10-29 MEDIUM 6.5 CVE-2016-2126EPSS 7% Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum.… Samba 4.3.13 / 4.4.8+ Fix from $1,6002017-05-11 HIGH 7.5 CVE-2016-2119 libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a clie… Samba 4.2.14 / 4.3.11+ Fix from $1,9502016-07-07 MEDIUM 5.9 CVE-2016-0771 The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, a… Samba Mitigation only Fix from $1,6002016-03-13 HIGH 7.5 CVE-2015-5330EPSS 6% ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, w… Samba Mitigation only Fix from $1,9502015-12-29