Samba is a widely deployed open-source implementation of the SMB/CIFS protocol that enables file sharing, print services, and directory integration across heterogeneous networks, serving as critical infrastructure in countless enterprise, hybrid-cloud, and legacy environments despite its single-product focus. The vendor's vulnerability profile reflects the complexity of protocol parsing and memory management in a decades-old codebase: a meaningful share of disclosures reach serious severity, and vulnerabilities have an elevated tendency to acquire public exploit code, making timely patching operationally urgent across distributed deployments. Recurring weakness classes center on buffer-boundary violations, input-validation lapses, and out-of-bounds reads that arise from handling untrusted network data and legacy protocol features, reinforcing the need for network segmentation and access controls around SMB services. Defenders should treat Samba advisories as high-priority given the protocol's role in identity services, file access, and lateral movement; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Samba over time
Signals from CVEs in this vendor scope (249 CVEs).
249 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2017-7494CRITICAL Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writ | May 30, 2017 | 9.8 | 98 | YES | YES |
CVE-2004-2687HIGH distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, | Dec 31, 2004 | 9.3 | 92 | NO | YES |
CVE-2015-0240HIGH The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on | Feb 24, 2015 | 10.0 | 89 | NO | YES |
CVE-2003-0201HIGH Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to | May 5, 2003 | 10.0 | 88 | NO | YES |
CVE-2012-1182HIGH The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validati | Apr 10, 2012 | 10.0 | 86 | NO | YES |
CVE-2010-2063HIGH Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial o | Jun 17, 2010 | 7.5 | 84 | NO | YES |
CVE-2007-2446HIGH Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involv | May 14, 2007 | 10.0 | 83 | NO | YES |
CVE-2003-0085HIGH Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitra | Mar 31, 2003 | 10.0 | 81 | NO | YES |
CVE-2024-12084CRITICAL A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG | Jan 15, 2025 | 9.8 | 75 | NO | NO |
Signals from CVEs in this vendor scope (249 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Samba.
Media articles that mention a CVE ID that affects a product developed by Samba — matched by CVE ID, not by vendor name.