Skip to main content

Vendor archive

mit CVEs

Beta · best-effort

156 CVEs tagged to vendor mit38 Critical, 42 High, 66 Medium, 10 Low, 0 Unrated.

CVE-2018-5710

Published Jan 16, 2018

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_lda…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5709

Published Jan 16, 2018

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15088

Published Nov 23, 2017

plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11462

Published Sep 13, 2017

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3120

Published Aug 1, 2016

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3119

Published Mar 26, 2016

The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.1…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8631

Published Feb 13, 2016

Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a de…

CVSS 6.5 · Medium

CVE-2015-8630

Published Feb 13, 2016

The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8629

Published Feb 13, 2016

The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exis…

CVSS 5.3 · Medium

CVE-2015-2698

Published Nov 13, 2015

The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a certain pointer, which allows…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2694

Published May 25, 2015

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attack…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5355

Published Feb 20, 2015

MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9423

Published Feb 19, 2015

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9422

Published Feb 19, 2015

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remot…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9421

Published Feb 19, 2015

The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly h…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5352

Published Feb 19, 2015

The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5354

Published Dec 16, 2014

plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a d…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-5353

Published Dec 16, 2014

The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows rem…

CVSS 3.5 · Low

CVE-2014-5351

Published Oct 10, 2014

The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold req…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4345

Published Aug 14, 2014

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x th…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 156 CVEsPage 2 of 7