Mit Kerberos 5 vulnerabilities
135 known vulnerabilities affecting mit/kerberos_5.
Total CVEs
135
CISA KEV
0
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL32HIGH35MEDIUM58LOW10
Vulnerabilities
Page 4 of 7
CVE-2011-4151P4HIGHCVSS 7.8v1.8v1.8.1+3 more2011-10-20
CVE-2011-4151 [HIGH] CVE-2011-4151: The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5
The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528.
nvd
CVE-2026-40355P4MEDIUMCVSS 5.9≥ 1.18, < 1.22.32026-04-28
CVE-2026-40355 [MEDIUM] CWE-476 CVE-2026-40355: In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application ca
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
nvd
CVE-2010-1322P4MEDIUMCVSS 6.5v1.8v1.8.1+2 more2010-10-07
CVE-2010-1322 [MEDIUM] CWE-20 CVE-2010-1322: The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5
The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information, spoof authorization, or execute arbitra
nvd
CVE-2014-9422P4MEDIUMCVSS 6.1v1.11v1.11.1+8 more2015-02-19
CVE-2014-9422 [MEDIUM] CWE-284 CVE-2014-9422: The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb
The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remote authenticated users to bypass a kadmin/* authorization check and obtain administrative access by leveraging access to a two-component principal with an initial "kadmind" su
nvd
CVE-2011-1529P4HIGHCVSS 7.8v1.8v1.8.1+5 more2011-10-20
CVE-2011-1529 [HIGH] CWE-20 CVE-2011-1529: The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5)
The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors.
nvd
CVE-2000-0514P4CRITICALCVSS 10.0v1.1v1.1.12000-06-14
CVE-2000-0514 [CRITICAL] CVE-2000-0514: GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which
GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.
nvd
CVE-2016-3120P4MEDIUMCVSS 6.5v1.13v1.13.1+8 more2016-08-01
CVE-2016-3120 [MEDIUM] CWE-476 CVE-2016-3120: The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos
The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a
nvd
CVE-2017-11368P4MEDIUMCVSS 6.5v1.7v1.7.1+41 more2017-08-09
CVE-2017-11368 [MEDIUM] CWE-617 CVE-2017-11368: In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion fail
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
nvd
CVE-2021-37750P4MEDIUMCVSS 6.5fixed in 1.18.5≥ 1.19.0, < 1.19.32021-08-23
CVE-2021-37750 [MEDIUM] CWE-476 CVE-2021-37750: The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
nvd
CVE-2010-1321P4MEDIUMCVSS 6.8≤ 1.7.1≥ 1.8, < 1.8.22010-05-19
CVE-2010-1321 [MEDIUM] CWE-476 CVE-2010-1321: The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (a
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash)
nvd
CVE-2015-2696P4HIGHCVSS 7.1fixed in 1.142015-11-09
CVE-2015-2696 [HIGH] CWE-18 CVE-2015-2696: lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.
nvd
CVE-2024-26461P4HIGHCVSS 7.5v1.21.22024-02-29
CVE-2024-26461 [HIGH] CWE-770 CVE-2024-26461: Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sea
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
nvd
CVE-2010-0283P4HIGHCVSS 7.8v1.7v1.7.12010-02-22
CVE-2010-0283 [HIGH] CWE-20 CVE-2010-0283: The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allo
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.
nvd
CVE-2015-8631P4MEDIUMCVSS 6.5fixed in 1.13.4≥ 1.14, < 1.14.12016-02-13
CVE-2015-8631 [MEDIUM] CWE-772 CVE-2015-8631: Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
nvd
CVE-2008-0063P4HIGHCVSS 7.5≤ 1.6.32008-03-19
CVE-2008-0063 [HIGH] CWE-908 CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
nvd
CVE-2002-2443P4MEDIUMCVSS 5.0fixed in 1.11.32013-05-29
CVE-2002-2443 [MEDIUM] CVE-2002-2443: schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not proper
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-199
nvd
CVE-2005-0488P4MEDIUMCVSS 5.0v1.3.42005-06-14
CVE-2005-0488 [MEDIUM] CVE-2005-0488: Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malic
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
nvd
CVE-2015-2695P4MEDIUMCVSS 5.0fixed in 1.142015-11-09
CVE-2015-2695 [MEDIUM] CWE-763 CVE-2015-2695: lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
nvd
CVE-2004-1189P4HIGHCVSS 7.2≤ 1.3.52004-12-31
CVE-2004-1189 [HIGH] CWE-787 CVE-2004-1189: The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5,
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based
nvd
CVE-2006-3083P4HIGHCVSS 7.2v1.4v1.4.1+3 more2006-08-09
CVE-2006-3083 [HIGH] CWE-399 CVE-2006-3083: The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.
The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.
nvd