Skip to main content

Vendor/product archive

mit / kerberos_5 CVEs

Beta · best-effort

137 CVEs tagged to mit / kerberos_534 Critical, 35 High, 58 Medium, 10 Low, 0 Unrated.

CVE-2009-4212

Published Jan 13, 2010

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow r…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3295

Published Dec 29, 2009

The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0846

Published Apr 9, 2009

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to caus…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2009-0844

Published Apr 9, 2009

The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and po…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0845

Published Mar 27, 2009

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-0063

Published Mar 19, 2008

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attacke…

CVSS 7.5 · High

CVE-2008-0947

Published Mar 19, 2008

Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0948

Published Mar 19, 2008

Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5894

Published Dec 6, 2007

The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and r…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5902

Published Dec 6, 2007

Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5972

Published Dec 6, 2007

Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NO…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4743

Published Sep 6, 2007

The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kad…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3999

Published Sep 5, 2007

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4000

Published Sep 5, 2007

The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properl…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3149

Published Jun 11, 2007

sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a mann…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6143

Published Dec 31, 2006

The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an unin…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 76-100 of 137 CVEsPage 4 of 6