Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Samba

First CVE: Sep 30, 1997Active for: 29 yearsTotal CVEs: 249
65.5
VTI Score
TOP TARGET

Samba is a widely deployed open-source implementation of the SMB/CIFS protocol that enables file sharing, print services, and directory integration across heterogeneous networks, serving as critical infrastructure in countless enterprise, hybrid-cloud, and legacy environments despite its single-product focus. The vendor's vulnerability profile reflects the complexity of protocol parsing and memory management in a decades-old codebase: a meaningful share of disclosures reach serious severity, and vulnerabilities have an elevated tendency to acquire public exploit code, making timely patching operationally urgent across distributed deployments. Recurring weakness classes center on buffer-boundary violations, input-validation lapses, and out-of-bounds reads that arise from handling untrusted network data and legacy protocol features, reinforcing the need for network segmentation and access controls around SMB services. Defenders should treat Samba advisories as high-priority given the protocol's role in identity services, file access, and lateral movement; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
249
Total CVEs
More Total CVEs than 100% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Samba over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 1997
28 years ago
Most Recent CVE
May 28, 2026
58 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (249 CVEs).

249 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-1472CRITICAL
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
CVE-2017-7494CRITICAL
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writ
May 30, 20179.898YESYES
CVE-2004-2687HIGH
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs,
Dec 31, 20049.392NOYES
CVE-2015-0240HIGH
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on
Feb 24, 201510.089NOYES
CVE-2003-0201HIGH
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to
May 5, 200310.088NOYES
CVE-2012-1182HIGH
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validati
Apr 10, 201210.086NOYES
CVE-2010-2063HIGH
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial o
Jun 17, 20107.584NOYES
CVE-2007-2446HIGH
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involv
May 14, 200710.083NOYES
CVE-2003-0085HIGH
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitra
Mar 31, 200310.081NOYES
CVE-2024-12084CRITICAL
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG
Jan 15, 20259.875NONO
View all 249 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products249 CVEs
8%
47%
39%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (5.6%)
Network133 (53.4%)
Unknown97 (39.0%)
Physical0 (0.0%)
Adjacent Network5 (2.0%)
Attack Complexity
Low107 (43.0%)
High45 (18.1%)
Unknown97 (39.0%)
User Interaction
None141 (56.6%)
Unknown97 (39.0%)
Required11 (4.4%)
Privileges Required
Low69 (27.7%)
High6 (2.4%)
None77 (30.9%)
Unknown97 (39.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (249 CVEs).

CISA KEV
2 CVEs
0.8% of CVEs· 99th percentile
Metasploit
12 CVEs
4.8% of CVEs· 98th percentile
Nuclei
2 CVEs
0.8% of CVEs· 95th percentile
ExploitDB
26 CVEs
10.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Samba.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Samba — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Samba's Products

View all 9 CNAs →

Top CWEs