Skip to main content

Vendor/product archive

heimdal_project / heimdal CVEs

Beta · best-effort

13 CVEs tagged to heimdal_project / heimdal3 Critical, 9 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-3116

Published Mar 27, 2023

The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45142

Published Mar 6, 2023

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44758

Published Dec 26, 2022

Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-44640

Published Dec 25, 2022

Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16860

Published Jul 31, 2019

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6594

Published Aug 28, 2017

The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4862

Published Dec 25, 2011

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Showing 1-13 of 13 CVEsPage 1 of 1