- EPSS 8.58%
- Veröffentlicht 28.09.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.
- EPSS 13.6%
- Veröffentlicht 18.08.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
- EPSS 1.25%
- Veröffentlicht 02.04.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of a...
- EPSS 2.55%
- Veröffentlicht 02.04.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its hea...
CVE-2003-0028
- EPSS 56.05%
- Veröffentlicht 25.03.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...
- EPSS 19.01%
- Veröffentlicht 19.02.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.
- EPSS 19.34%
- Veröffentlicht 19.02.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
CVE-2003-0059
- EPSS 3.22%
- Veröffentlicht 19.02.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.
CVE-2003-0060
- EPSS 9.13%
- Veröffentlicht 19.02.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerbe...
- EPSS 32.92%
- Veröffentlicht 04.11.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before...