VYPR

Kerberos 5

by Mit

Source repositories

CVEs (147)

  • CVE-2006-3084Aug 9, 2006
    risk 0.00cvss —epss 0.01

    The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE:…

  • CVE-2005-1174Jul 18, 2005
    risk 0.00cvss —epss 0.05

    MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.

  • CVE-2004-0971Feb 9, 2005
    risk 0.00cvss —epss 0.00

    The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

  • CVE-2004-1189Dec 31, 2004
    risk 0.00cvss —epss 0.01

    The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error…

  • CVE-2004-0644Sep 28, 2004
    risk 0.00cvss —epss 0.06

    The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.

  • CVE-2003-0082Apr 2, 2003
    risk 0.00cvss —epss 0.03

    The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").

  • CVE-2003-0072Apr 2, 2003
    risk 0.00cvss —epss 0.02

    The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").

  • CVE-2003-0138Mar 24, 2003
    risk 0.00cvss —epss 0.04

    Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.

  • CVE-2003-0139Mar 24, 2003
    risk 0.00cvss —epss 0.04

    Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket…

  • CVE-2002-0036Feb 19, 2003
    risk 0.00cvss —epss 0.05

    Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.

  • CVE-2003-0060Feb 19, 2003
    risk 0.00cvss —epss 0.06

    Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.

  • CVE-2003-0058Feb 19, 2003
    risk 0.00cvss —epss 0.05

    MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.

  • CVE-2003-0059Feb 19, 2003
    risk 0.00cvss —epss 0.04

    Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.

  • CVE-2001-0417Jun 27, 2001
    risk 0.00cvss —epss 0.00

    Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.

  • CVE-2001-1323May 16, 2001
    risk 0.00cvss —epss 0.04

    Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob…

  • CVE-2000-0514Jun 14, 2000
    risk 0.00cvss —epss 0.03

    GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.

  • CVE-2000-0549Jun 9, 2000
    risk 0.00cvss —epss 0.02

    Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.

  • CVE-2000-0547Jun 9, 2000
    risk 0.00cvss —epss 0.03

    Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.

  • CVE-2000-0548Jun 9, 2000
    risk 0.00cvss —epss 0.03

    Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.

  • CVE-2000-0550Jun 9, 2000
    risk 0.00cvss —epss 0.02

    Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.

Page 7 of 8