CVE-2010-1322
- EPSS 1.46%
- Veröffentlicht 07.10.2010 21:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of s...
CVE-2010-1321
- EPSS 1.86%
- Veröffentlicht 19.05.2010 18:30:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...
- EPSS 22.07%
- Veröffentlicht 22.04.2010 14:30:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code ...
CVE-2010-0629
- EPSS 2.28%
- Veröffentlicht 07.04.2010 15:30:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an inva...
- EPSS 0.93%
- Veröffentlicht 25.03.2010 22:30:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failu...
CVE-2010-0283
- EPSS 3.73%
- Veröffentlicht 22.02.2010 13:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.
- EPSS 16.49%
- Veröffentlicht 13.01.2010 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly...
- EPSS 2.74%
- Veröffentlicht 29.12.2009 20:41:19
- Zuletzt bearbeitet 23.04.2026 00:35:47
The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer deref...
CVE-2009-0844
- EPSS 3.43%
- Veröffentlicht 09.04.2009 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that tri...
- EPSS 50.01%
- Veröffentlicht 09.04.2009 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...