Kth Kerberos vulnerabilities
8 known vulnerabilities affecting kth/kth_kerberos.
Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2002-0600HIGHCVSS 7.5v4_1.0.2v4_1.0.3+2 more2002-06-18
CVE-2002-0600 [HIGH] CVE-2002-0600: Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute ar
Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
nvd
CVE-2001-1444HIGHCVSS 7.5v4v52001-08-27
CVE-2001-1444 [HIGH] CVE-2001-1444: The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not e
The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack.
nvd
CVE-2001-1443MEDIUMCVSS 5.0v4v52001-08-27
CVE-2001-1443 [MEDIUM] CVE-2001-1443: KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server
KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.
nvd
CVE-2001-0033HIGHCVSS 7.2v42001-02-16
CVE-2001-0033 [HIGH] CVE-2001-0033: KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an el
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.
nvd
CVE-2001-0034HIGHCVSS 7.2PoC≤ 4.1.0.32001-02-16
CVE-2001-0034 [HIGH] CVE-2001-0034: KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, whic
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.
nvd
CVE-2001-0035HIGHCVSS 7.2v42001-02-16
CVE-2001-0035 [HIGH] CVE-2001-0035: Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.
nvd
CVE-2001-0036LOWCVSS 1.2v42001-02-16
CVE-2001-0036 [LOW] CVE-2001-0036: KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket fil
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.
nvd
CVE-1999-1099MEDIUMCVSS 5.0v41996-11-22
CVE-1999-1099 [MEDIUM] CVE-1999-1099: Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that g
Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.
nvd