← Back

Kth Kerberos

kth_kerberos

Vendor: Kth • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Kth
Luke Mewburn
2Kth Kerberos
Lukemftp
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
1Kth
1Kth Kerberos
Apr 16, 2026
Aug 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentica...Show more
The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack.Show less
1Kth
1Kth Kerberos
Apr 16, 2026
Aug 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle...Show more
KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.Show less
1Kth
1Kth Kerberos
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.
1Kth
1Kth Kerberos
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.
1Kth
1Kth Kerberos
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.
2Kth
Netbsd
2Kth Kerberos
Netbsd
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the...Show more
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.Show less
1Kth
1Kth Kerberos
Apr 16, 2026
Nov 22, 1996
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.