CVE-2010-1323
- EPSS 2.85%
- Veröffentlicht 02.12.2010 16:22:20
- Zuletzt bearbeitet 16.06.2026 23:18:07
MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distrib...
CVE-2010-1324
- EPSS 2.25%
- Veröffentlicht 02.12.2010 16:22:20
- Zuletzt bearbeitet 16.06.2026 23:18:08
MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum,...
CVE-2010-1322
- EPSS 3.04%
- Veröffentlicht 07.10.2010 21:00:01
- Zuletzt bearbeitet 16.06.2026 23:18:07
The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of s...
CVE-2010-1321
- EPSS 6.88%
- Veröffentlicht 19.05.2010 18:30:03
- Zuletzt bearbeitet 16.06.2026 23:18:07
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...
- EPSS 11.86%
- Veröffentlicht 22.04.2010 14:30:01
- Zuletzt bearbeitet 16.06.2026 23:18:07
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code ...
CVE-2010-0629
- EPSS 5.47%
- Veröffentlicht 07.04.2010 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:32
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an inva...
- EPSS 3.33%
- Veröffentlicht 25.03.2010 22:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:31
The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failu...
CVE-2010-0283
- EPSS 2.43%
- Veröffentlicht 22.02.2010 13:00:02
- Zuletzt bearbeitet 16.06.2026 23:15:51
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.
- EPSS 7.41%
- Veröffentlicht 13.01.2010 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:13:15
Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly...
- EPSS 40.35%
- Veröffentlicht 29.12.2009 20:41:19
- Zuletzt bearbeitet 16.06.2026 23:11:19
The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer deref...