Skip to main content

Vendor archive

gss-ntlmssp_project CVEs

Beta · best-effort

5 CVEs tagged to vendor gss-ntlmssp_project0 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-25567

Published Feb 14, 2023

GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25566

Published Feb 14, 2023

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25565

Published Feb 14, 2023

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, an incorrect free when decoding target information can trigger…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25564

Published Feb 14, 2023

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, memory corruption can be triggered when decoding UTF16 strings…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25563

Published Feb 14, 2023

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM fields can tri…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1