Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kerberos 5 HIGH 7.2
CVE-2007-3149

sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users…

Mitigation only
Fix from $1,950 2007-06-11
Kerberos 5 MEDIUM 5.0
CVE-2006-6144EPSS 5%

The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and…

Fix: after 1.5.1
Fix from $1,600 2006-12-31
Kerberos 5 HIGH 7.5
CVE-2005-1175EPSS 8%

Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial …

Patch available
Fix from $1,950 2005-07-18
Kerberos 5 MEDIUM 5.0
CVE-2005-1174EPSS 5%

MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a …

Patch available
Fix from $1,600 2005-07-18
Kerberos 5 HIGH 7.2
CVE-2004-1189

The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not prop…

Fix: after 1.3.5
Fix from $1,950 2004-12-31
Kerberos 5 MEDIUM 5.0
CVE-2004-0644EPSS 6%

The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of…

Patch available
Fix from $1,600 2004-09-28
Kerberos HIGH 10.0
CVE-2004-0523EPSS 12%

Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as …

Patch available
Fix from $1,950 2004-08-18
Cgiemail MEDIUM 5.0
CVE-2002-1575

cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "requir…

Patch available
Fix from $1,600 2004-03-03
Kerberos MEDIUM 5.0
CVE-2003-0072

The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) …

Patch available
Fix from $1,600 2003-04-02
Kerberos MEDIUM 5.0
CVE-2003-0082

The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) …

Patch available
Fix from $1,600 2003-04-02
Kerberos HIGH 7.5
CVE-2003-0138

Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a ch…

Patch available
Fix from $1,950 2003-03-24
Kerberos HIGH 7.5
CVE-2003-0139

Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key …

Patch available
Fix from $1,950 2003-03-24
Kerberos 5 HIGH 7.5
CVE-2003-0059

Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in …

Patch available
Fix from $1,950 2003-02-19
Kerberos 5 HIGH 7.5
CVE-2003-0060EPSS 6%

Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause …

Patch available
Fix from $1,950 2003-02-19
Kerberos 5 MEDIUM 5.0
CVE-2002-0036

Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned…

Patch available
Fix from $1,600 2003-02-19
Kerberos 5 MEDIUM 5.0
CVE-2003-0058

MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within …

Patch available
Fix from $1,600 2003-02-19
Cgiemail HIGH 7.5
CVE-2002-1652EPSS 8%

Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a l…

Patch available
Fix from $1,950 2002-12-31
Pgp Public Key Server HIGH 7.5
CVE-2002-0900EPSS 6%

Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbit…

Patch available
Fix from $1,950 2002-10-04
Kerberos 5 HIGH 7.5
CVE-2001-1323

Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code v…

Fix: 1.2.2+
Fix from $1,950 2001-05-16
Kerberos 5 HIGH 10.0
CVE-2000-0514

GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of serv…

Patch available
Fix from $1,950 2000-06-14
Kerberos HIGH 7.5
CVE-1999-1321

Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands …

Mitigation only
Fix from $1,950 1998-11-05
Kerberos 5 HIGH 7.2
CVE-1999-1296

Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos…

Mitigation only
Fix from $1,950 1997-04-29