CVE-2014-4345
- EPSS 11.3%
- Veröffentlicht 14.08.2014 05:01:50
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) 1.6.x through 1.11.x before 1.11.6 and 1.12.x before 1.12.2 allows remote authe...
CVE-2014-4343
- EPSS 7.38%
- Veröffentlicht 14.08.2014 05:01:49
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corru...
CVE-2014-4344
- EPSS 5.27%
- Veröffentlicht 14.08.2014 05:01:49
- Zuletzt bearbeitet 06.05.2026 22:30:45
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) ...
- EPSS 14.45%
- Veröffentlicht 20.07.2014 11:12:50
- Zuletzt bearbeitet 06.05.2026 22:30:45
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.
- EPSS 8.14%
- Veröffentlicht 20.07.2014 11:12:50
- Zuletzt bearbeitet 06.05.2026 22:30:45
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
CVE-2013-1417
- EPSS 0.54%
- Veröffentlicht 20.11.2013 14:12:44
- Zuletzt bearbeitet 29.04.2026 01:13:23
do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that tr...
CVE-2013-1418
- EPSS 7.67%
- Veröffentlicht 18.11.2013 03:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon ...
- EPSS 0.77%
- Veröffentlicht 18.11.2013 02:55:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
An unspecified third-party database module for the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request, a d...
- EPSS 15.01%
- Veröffentlicht 29.05.2013 14:29:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a for...
- EPSS 2.27%
- Veröffentlicht 19.04.2013 11:44:26
- Zuletzt bearbeitet 29.04.2026 01:13:23
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of s...