Skip to main content

Vendor/product archive

mit / kerberos_5 CVEs

Beta · best-effort

137 CVEs tagged to mit / kerberos_534 Critical, 35 High, 58 Medium, 10 Low, 0 Unrated.

CVE-2026-40356

Published Apr 28, 2026

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a Nego…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-40355

Published Apr 28, 2026

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in…

CVSS 5.9 · Medium
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2024-37371

Published Jun 28, 2024

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-37370

Published Jun 28, 2024

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear tru…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39975

Published Aug 16, 2023

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. I…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28196

Published Nov 6, 2020

MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support…

CVSS 7.5 · High

CVE-2019-14844

Published Sep 26, 2019

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15088

Published Nov 23, 2017

plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11462

Published Sep 13, 2017

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3120

Published Aug 1, 2016

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3119

Published Mar 26, 2016

The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.1…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8631

Published Feb 13, 2016

Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a de…

CVSS 6.5 · Medium

CVE-2015-8630

Published Feb 13, 2016

The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 137 CVEsPage 1 of 6