Mit

Kerberos 5

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.97%
  • Veröffentlicht 16.12.2014 23:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...

  • EPSS 2.62%
  • Veröffentlicht 10.10.2014 01:55:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by lever...

  • EPSS 8.09%
  • Veröffentlicht 14.08.2014 05:01:50
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authe...

  • EPSS 6.42%
  • Veröffentlicht 14.08.2014 05:01:49
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corru...

  • EPSS 6.61%
  • Veröffentlicht 14.08.2014 05:01:49
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) ...

  • EPSS 7.14%
  • Veröffentlicht 20.07.2014 11:12:50
  • Zuletzt bearbeitet 06.05.2026 22:30:45

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

  • EPSS 6.52%
  • Veröffentlicht 20.07.2014 11:12:50
  • Zuletzt bearbeitet 06.05.2026 22:30:45

MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.

Exploit
  • EPSS 1.93%
  • Veröffentlicht 20.11.2013 14:12:44
  • Zuletzt bearbeitet 29.04.2026 01:13:23

do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that tr...

  • EPSS 5.51%
  • Veröffentlicht 18.11.2013 03:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon ...

  • EPSS 2.61%
  • Veröffentlicht 18.11.2013 02:55:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

An unspecified third-party database module for the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request, a d...