Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rsync HIGH 7.0
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect …

Fix: 3.4.3+
Fix from $1,950 2026-05-20
Rsync HIGH 8.1
CVE-2026-43618

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked …

Fix: after 3.4.2
Fix from $1,950 2026-05-20
Rsync MEDIUM 6.3
CVE-2026-43619

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unli…

Fix: after 3.4.2
Fix from $1,600 2026-05-20
Rsync MEDIUM 5.5
CVE-2026-43620

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rs…

Fix: after 3.4.2
Fix from $1,600 2026-05-20
Rsync HIGH 7.8
CVE-2026-41035

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim…

Fix: after 3.4.1
Fix from $1,950 2026-04-16
Samba MEDIUM 6.5
CVE-2023-4154

A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Re…

Fix: 4.17.12 / 4.18.8+
Fix from $1,600 2023-11-07
Samba MEDIUM 6.5
CVE-2023-5568

A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a d…

Fix: 4.19.2+
Fix from $1,600 2023-10-25
Samba MEDIUM 5.9
CVE-2023-0922

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conn…

Fix: 4.16.10 / 4.17.7+
Fix from $1,600 2023-04-03
Samba MEDIUM 6.5
CVE-2023-0614

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may b…

Fix: 4.16.10 / 4.17.7+
Fix from $1,600 2023-04-03
Samba CRITICAL 9.8
CVE-2022-45141

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that …

Fix: 4.15.13 / 4.16.8+
Fix from $2,300 2023-03-06
Ppp MEDIUM 6.5
CVE-2022-4603

A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppd…

Fix: 2.5.0+
Fix from $1,600 2022-12-18
Samba HIGH 8.8
CVE-2022-32744

A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own ke…

Fix: 4.14.14 / 4.15.9+
Fix from $1,950 2022-08-25
Samba HIGH 8.1
CVE-2022-32745

A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting…

Fix: 4.14.14 / 4.15.9+
Fix from $1,950 2022-08-25
Samba MEDIUM 5.4
CVE-2022-32746

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database mo…

Fix: 4.14.14 / 4.15.9+
Fix from $1,600 2022-08-25
Samba HIGH 8.8
CVE-2022-2031

A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them t…

Fix: 4.14.14 / 4.15.9+
Fix from $1,950 2022-08-25
Samba HIGH 8.8
CVE-2020-25721

Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a …

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-03-16
Samba HIGH 8.8
CVE-2021-3738

In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'.…

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-03-02
Samba HIGH 7.5
CVE-2021-23192

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an …

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-03-02
Rsync HIGH 7.4
CVE-2020-14387

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthentic…

Fix: 3.2.4+
Fix from $1,950 2021-05-27
Samba HIGH 7.5
CVE-2018-16860

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, exclud…

Fix: 4.8.12 / 4.9.8+
Fix from $1,950 2019-07-31
Samba MEDIUM 6.5
CVE-2019-12435

Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS mana…

Fix: 4.9.9 / 4.10.5+
Fix from $1,600 2019-06-19
Samba MEDIUM 5.9
CVE-2018-16853

Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerb…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Samba MEDIUM 5.9
CVE-2018-16857

Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) …

Fix: 4.9.3+
Fix from $1,600 2018-11-28
Samba HIGH 8.8
CVE-2016-2123EPSS 6%

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-cont…

Fix: 4.3.13 / 4.4.8+
Fix from $1,950 2018-11-01
Samba MEDIUM 6.5
CVE-2018-1140EPSS 11%

A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause …

Fix: 4.8.4+
Fix from $1,600 2018-08-22
Rsync CRITICAL 9.8
CVE-2017-15994

rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrict…

Fix: after 3.1.2
Fix from $2,300 2017-10-29
Samba MEDIUM 6.5
CVE-2016-2126EPSS 7%

Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum.…

Fix: 4.3.13 / 4.4.8+
Fix from $1,600 2017-05-11
Samba HIGH 7.5
CVE-2016-2119

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a clie…

Fix: 4.2.14 / 4.3.11+
Fix from $1,950 2016-07-07
Samba MEDIUM 5.9
CVE-2016-0771

The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, a…

Mitigation only
Fix from $1,600 2016-03-13
Samba HIGH 7.5
CVE-2015-5330EPSS 6%

ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, w…

Mitigation only
Fix from $1,950 2015-12-29