Skip to main content

Vendor/product archive

mit / kerberos CVEs

Beta · best-effort

31 CVEs tagged to mit / kerberos6 Critical, 5 High, 17 Medium, 3 Low, 0 Unrated.

CVE-2018-20217

Published Dec 26, 2018

A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DE…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5710

Published Jan 16, 2018

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_lda…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5709

Published Jan 16, 2018

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5354

Published Dec 16, 2014

plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a d…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6800

Published Nov 18, 2013

An unspecified third-party database module for the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x allows remote authenticated users to cause a denial of service…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0282

Published Feb 10, 2011

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0281

Published Feb 10, 2011

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a de…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1323

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-0283

Published Feb 22, 2010

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4212

Published Jan 13, 2010

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow r…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0847

Published Apr 9, 2009

The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash)…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0844

Published Apr 9, 2009

The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and po…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0845

Published Mar 27, 2009

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2003-0072

Published Apr 2, 2003

The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0082

Published Apr 2, 2003

The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0138

Published Mar 24, 2003

Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0139

Published Mar 24, 2003

Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0417

Published Jun 27, 2001

Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2