Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kerberos 5 HIGH 9.0
CVE-2012-1014

The process_as_req function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x before 1.10.3 does not initialize a certain stru…

Patch available
Fix from $1,950 2012-08-06
Kerberos 5 MEDIUM 5.5
CVE-2012-1012

server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) …

Mitigation only
Fix from $1,600 2012-06-07
Mit Kerberos MEDIUM 6.8
CVE-2011-1530

The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authen…

Patch available
Fix from $1,600 2011-12-08
Kerberos 5 HIGH 7.8
CVE-2011-4151

The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley D…

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 7.8
CVE-2011-1527

The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remot…

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 7.8
CVE-2011-1528

The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when …

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 7.8
CVE-2011-1529

The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when th…

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 10.0
CVE-2011-0285EPSS 21%

The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an …

Patch available
Fix from $1,950 2011-04-15
Kerberos 5 HIGH 7.6
CVE-2011-0284EPSS 8%

Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 throu…

Patch available
Fix from $1,950 2011-03-20
Kerberos MEDIUM 5.0
CVE-2011-0281

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows …

Mitigation only
Fix from $1,600 2011-02-10
Kerberos MEDIUM 5.0
CVE-2011-0282

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2011-02-10
Kerberos 5 MEDIUM 5.0
CVE-2011-0283

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 allows remote attackers to cause a denial of service (NULL pointer dereference and…

Mitigation only
Fix from $1,600 2011-02-10
Kerberos 5 MEDIUM 5.0
CVE-2010-4022

The do_standalone function in the MIT krb5 KDC database propagation daemon (kpropd) in Kerberos 1.7, 1.8, and 1.9, when running in standalone mode, d…

Patch available
Fix from $1,600 2011-02-10
Kerberos 5 MEDIUM 6.3
CVE-2010-4020

MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (…

Patch available
Fix from $1,600 2010-12-02
Kerberos 5 MEDIUM 6.5
CVE-2010-1322

The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly …

Patch available
Fix from $1,600 2010-10-07
Kerberos 5 MEDIUM 5.0
CVE-2010-0628

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 be…

Patch available
Fix from $1,600 2010-03-25
Kerberos HIGH 7.8
CVE-2010-0283

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,950 2010-02-22
Kerberos HIGH 10.0
CVE-2009-4212EPSS 7%

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3,…

Patch available
Fix from $1,950 2010-01-13
Kerberos 5 MEDIUM 5.0
CVE-2009-3295EPSS 40%

The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5…

Patch available
Fix from $1,600 2009-12-29
Kerberos MEDIUM 5.8
CVE-2009-0844

The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of…

Mitigation only
Fix from $1,600 2009-04-09
Kerberos MEDIUM 5.0
CVE-2009-0845EPSS 6%

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, al…

No fix yet
Fix from $1,600 2009-03-27
Kerberos 5 HIGH 10.0
CVE-2008-0947EPSS 9%

Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-03-19
Kerberos 5 HIGH 9.3
CVE-2008-0948EPSS 7%

Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versio…

Mitigation only
Fix from $1,950 2008-03-19
Kerberos 5 HIGH 10.0
CVE-2007-5902EPSS 6%

Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unkn…

No fix yet
Fix from $1,950 2007-12-06
Kerberos 5 HIGH 9.3
CVE-2007-5894

The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, …

Mitigation only
Fix from $1,950 2007-12-06
Kerberos 5 HIGH 9.0
CVE-2007-5972

Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote aut…

Mitigation only
Fix from $1,950 2007-12-06
Kerberos 5 MEDIUM 6.9
CVE-2007-5901

Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and…

Fix: after 1.6.3_kdc
Fix from $1,600 2007-12-06
Kerberos 5 MEDIUM 6.9
CVE-2007-5971

Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact an…

Fix: after 1.6.3_kdc
Fix from $1,600 2007-12-06
Kerberos 5 HIGH 10.0
CVE-2007-4743

The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerbe…

Patch available
Fix from $1,950 2007-09-06
Kerberos 5 HIGH 10.0
CVE-2007-3999EPSS 11%

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerber…

Mitigation only
Fix from $1,950 2007-09-05