Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kerberos 5 HIGH 7.5
CVE-2026-40356

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_con…

Fix: after 1.22.2
Fix from $1,950 2026-04-28
Kerberos 5 HIGH 7.5
CVE-2026-40355

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a N…

Fix: after 1.22.2
Fix from $1,950 2026-04-28
Kerberos 5 HIGH 7.5
CVE-2024-37370

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the…

Fix: 1.21.3+
Fix from $1,950 2024-06-28
Kerberos 5 HIGH 7.5
CVE-2024-26461

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

No fix yet
Fix from $1,950 2024-02-29
Kerberos 5 MEDIUM 5.5
CVE-2024-26462

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.

No fix yet
Fix from $1,600 2024-02-29
Kerberos 5 MEDIUM 5.3
CVE-2024-26458

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.

No fix yet
Fix from $1,600 2024-02-29
Kerberos 5 HIGH 8.8
CVE-2023-39975

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authoriz…

Fix: 1.21.2+
Fix from $1,950 2023-08-16
Kerberos 5 HIGH 8.8
CVE-2022-42898EPSS 6%

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC,…

Fix: 1.19.4 / 4.15.12+
Fix from $1,950 2022-12-25
Scratch Svg Renderer MEDIUM 6.1
CVE-2020-27428

A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a c…

Patch available
Fix from $1,600 2022-01-06
Universal Turing Machine HIGH 7.8
CVE-2021-32471

Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code…

No fix yet
Fix from $1,950 2021-05-10
Krb5 Appl HIGH 7.5
CVE-2019-25018

In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filen…

Fix: after 1.0.3
Fix from $1,950 2021-02-02
Krb5 Appl MEDIUM 5.9
CVE-2019-25017

An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which fi…

Fix: after 1.0.3
Fix from $1,600 2021-02-02
Scratch Svg Renderer CRITICAL 9.6
CVE-2020-7750EPSS 6%

This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can…

Patch available
Fix from $2,300 2020-10-21
Scratch Vm CRITICAL 9.8
CVE-2020-14000

MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certa…

Fix: 0.2.0-prerelease.20200714185213+
Fix from $2,300 2020-07-16
Kerberos HIGH 7.5
CVE-2018-5709

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 1…

Fix: after 5-1.16
Fix from $1,950 2018-01-16
Kerberos MEDIUM 6.5
CVE-2018-5710

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value …

Fix: after 5-1.16
Fix from $1,600 2018-01-16
Kerberos 5 CRITICAL 9.8
CVE-2017-15088EPSS 8%

plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows re…

Fix: after 1.15.2
Fix from $2,300 2017-11-23
Kerberos 5 MEDIUM 6.5
CVE-2016-3120

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.…

Patch available
Fix from $1,600 2016-08-01
Kerberos 5 HIGH 7.5
CVE-2015-8630

The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.…

Patch available
Fix from $1,950 2016-02-13
Kerberos 5 HIGH 8.5
CVE-2015-2698

The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a…

Patch available
Fix from $1,950 2015-11-13
Kerberos 5 MEDIUM 5.8
CVE-2015-2694

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validat…

Patch available
Fix from $1,600 2015-05-25
Kerberos 5 MEDIUM 5.0
CVE-2014-5355

MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' charac…

Patch available
Fix from $1,600 2015-02-20
Kerberos 5 MEDIUM 5.0
CVE-2014-9423

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and …

Patch available
Fix from $1,600 2015-02-19
Kerberos 5 MEDIUM 6.1
CVE-2014-9422

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.1…

Patch available
Fix from $1,600 2015-02-19
Kerberos 5 HIGH 9.0
CVE-2014-9421EPSS 6%

The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x bef…

Patch available
Fix from $1,950 2015-02-19
Kerberos 5 HIGH 9.0
CVE-2014-5352EPSS 6%

The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) thr…

Patch available
Fix from $1,950 2015-02-19
Kerberos 5 HIGH 8.5
CVE-2014-4345EPSS 8%

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT …

Patch available
Fix from $1,950 2014-08-14
Kerberos 5 MEDIUM 5.0
CVE-2013-1415

The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC…

Fix: 1.10.4+
Fix from $1,600 2013-03-05
Kerberos 5 MEDIUM 5.0
CVE-2012-1016

The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in …

Fix: 1.10.4+
Fix from $1,600 2013-03-05
Kerberos 5 HIGH 9.3
CVE-2012-1015

The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x…

Patch available
Fix from $1,950 2012-08-06