Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kerberos vulnerabilities and exploits
(subscribe to this query)
2.1
CVSSv2
CVE-2010-4021
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "KrbFastReq forgery i...
Mit Kerberos 5 1.7
7.2
CVSSv2
CVE-2001-0035
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote malicious users to cause a denial of service and possibly execute arbitrary commands via a long authentication request.
Kth Kth Kerberos 4
5
CVSSv2
CVE-2009-3295
The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 prior to 1.7.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon cras...
Mit Kerberos 5 1.7
4.6
CVSSv2
CVE-1999-0143
Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.
Process Software Multinet 3.4
Mit Kerberos 4.0
Process Software Multinet 3.5
Mit Kerberos 5 -
Sun Sunos 5.3
Sun Sunos 5.4
8.5
CVSSv2
CVE-2007-4000
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 up to and including 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authentica...
Mit Kerberos 5
Fedoraproject Fedora 7
7.2
CVSSv2
CVE-2001-0033
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.
Kth Kth Kerberos 4
Netbsd Netbsd 1.5
7.2
CVSSv2
CVE-2007-3149
sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: anot...
Mit Kerberos 5 -
Todd Miller Sudo 1.6.8 P12
6.8
CVSSv2
CVE-2020-3125
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote malicious user to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is confi...
Cisco Asa 5505 Firmware 9.10\\(1.220\\)
Cisco Asa 5510 Firmware 9.10\\(1.220\\)
Cisco Asa 5512-x Firmware 9.10\\(1.220\\)
Cisco Asa 5515-x Firmware 9.10\\(1.220\\)
Cisco Asa 5520 Firmware 9.10\\(1.220\\)
Cisco Asa 5525-x Firmware 9.10\\(1.220\\)
Cisco Asa 5540 Firmware 9.10\\(1.220\\)
Cisco Asa 5545-x Firmware 9.10\\(1.220\\)
Cisco Asa 5550 Firmware 9.10\\(1.220\\)
Cisco Asa 5555-x Firmware 9.10\\(1.220\\)
Cisco Asa 5580 Firmware 9.10\\(1.220\\)
Cisco Asa 5585-x Firmware 9.10\\(1.220\\)
Cisco Adaptive Security Appliance Software
1 Article
7.2
CVSSv2
CVE-1999-0713
The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.
Mit Kerberos 5 -
Cde Cde
Transarc Afs
Digital Unix
7.5
CVSSv2
CVE-2004-0772
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and previous versions may allow remote malicious users to execute arbitrary code.
Mit Kerberos 5
Openpkg Openpkg 2.0
Openpkg Openpkg 2.1
Debian Debian Linux 3.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »