Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_con… Kerberos 5 after 1.22.2 Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a N… Kerberos 5 after 1.22.2 Fix from $1,9502026-04-28 HIGH 7.5 CVE-2024-37370 In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the… Kerberos 5 1.21.3+ Fix from $1,9502024-06-28 HIGH 7.5 CVE-2024-26461 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. Kerberos 5 No fix yet Fix from $1,9502024-02-29 MEDIUM 5.5 CVE-2024-26462 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. Kerberos 5 No fix yet Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-26458 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. Kerberos 5 No fix yet Fix from $1,6002024-02-29 HIGH 8.8 CVE-2023-39975 kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authoriz… Kerberos 5 1.21.2+ Fix from $1,9502023-08-16 HIGH 8.8 CVE-2022-42898EPSS 6% PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC,… Kerberos 5 1.19.4 / 4.15.12+ Fix from $1,9502022-12-25 MEDIUM 6.1 CVE-2020-27428 A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a c… Scratch Svg Renderer Patch available Fix from $1,6002022-01-06 HIGH 7.8 CVE-2021-32471 Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code… Universal Turing Machine No fix yet Fix from $1,9502021-05-10 HIGH 7.5 CVE-2019-25018 In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filen… Krb5 Appl after 1.0.3 Fix from $1,9502021-02-02 MEDIUM 5.9 CVE-2019-25017 An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which fi… Krb5 Appl after 1.0.3 Fix from $1,6002021-02-02 CRITICAL 9.6 CVE-2020-7750EPSS 6% This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can… Scratch Svg Renderer Patch available Fix from $2,3002020-10-21 CRITICAL 9.8 CVE-2020-14000 MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certa… Scratch Vm 0.2.0-prerelease.20200714185213+ Fix from $2,3002020-07-16 HIGH 7.5 CVE-2018-5709 An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 1… Kerberos after 5-1.16 Fix from $1,9502018-01-16 MEDIUM 6.5 CVE-2018-5710 An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value … Kerberos after 5-1.16 Fix from $1,6002018-01-16 CRITICAL 9.8 CVE-2017-15088EPSS 8% plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows re… Kerberos 5 after 1.15.2 Fix from $2,3002017-11-23 MEDIUM 6.5 CVE-2016-3120 The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.… Kerberos 5 Patch available Fix from $1,6002016-08-01 HIGH 7.5 CVE-2015-8630 The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.… Kerberos 5 Patch available Fix from $1,9502016-02-13 HIGH 8.5 CVE-2015-2698 The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a… Kerberos 5 Patch available Fix from $1,9502015-11-13 MEDIUM 5.8 CVE-2015-2694 The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validat… Kerberos 5 Patch available Fix from $1,6002015-05-25 MEDIUM 5.0 CVE-2014-5355 MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' charac… Kerberos 5 Patch available Fix from $1,6002015-02-20 MEDIUM 5.0 CVE-2014-9423 The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and … Kerberos 5 Patch available Fix from $1,6002015-02-19 MEDIUM 6.1 CVE-2014-9422 The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.1… Kerberos 5 Patch available Fix from $1,6002015-02-19 HIGH 9.0 CVE-2014-9421EPSS 6% The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x bef… Kerberos 5 Patch available Fix from $1,9502015-02-19 HIGH 9.0 CVE-2014-5352EPSS 6% The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) thr… Kerberos 5 Patch available Fix from $1,9502015-02-19 HIGH 8.5 CVE-2014-4345EPSS 8% Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT … Kerberos 5 Patch available Fix from $1,9502014-08-14 MEDIUM 5.0 CVE-2013-1415 The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC… Kerberos 5 1.10.4+ Fix from $1,6002013-03-05 MEDIUM 5.0 CVE-2012-1016 The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in … Kerberos 5 1.10.4+ Fix from $1,6002013-03-05 HIGH 9.3 CVE-2012-1015 The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x… Kerberos 5 Patch available Fix from $1,9502012-08-06