CVE-2017-11462
- EPSS 1.06%
- Veröffentlicht 13.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
CVE-2017-11368
- EPSS 0.68%
- Veröffentlicht 09.08.2017 18:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
CVE-2016-3120
- EPSS 3.26%
- Veröffentlicht 01.08.2016 02:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows r...
CVE-2016-3119
- EPSS 9.15%
- Veröffentlicht 26.03.2016 01:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users...
CVE-2015-8631
- EPSS 2.21%
- Veröffentlicht 13.02.2016 02:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL pr...
CVE-2015-8630
- EPSS 3.01%
- Veröffentlicht 13.02.2016 02:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a de...
CVE-2015-8629
- EPSS 1.61%
- Veröffentlicht 13.02.2016 02:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensit...
CVE-2015-2698
- EPSS 0.87%
- Veröffentlicht 13.11.2015 03:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a certain pointer, which allows remote authenticated users to cause a denial of service (memory corrup...
- EPSS 5.45%
- Veröffentlicht 09.11.2015 03:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field...
CVE-2015-2696
- EPSS 10.77%
- Veröffentlicht 09.11.2015 03:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...