Heimdal Project
heimdal_project
13 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash. |
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and...Show more |
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept. |
3Heimdal Project MitSamba3Heimdal Kerberos 5SambaJun 17, 2026 Dec 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms...Show more |
2Heimdal Project Samba2Heimdal SambaJun 17, 2026 Dec 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). |
2Debian Heimdal Project2Debian Linux HeimdalJun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) a...Show more |
2Heimdal Project Samba2Heimdal SambaNov 21, 2024 Jul 31, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could...Show more |
4Debian FedoraprojectHeimdal Project+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 May 15, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. |
2Debian Heimdal Project2Debian Linux HeimdalMay 13, 2026 Dec 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL...Show more |
2Heimdal Project Opensuse2Heimdal LeapMay 13, 2026 Aug 28, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets. |
5Apple DebianFreebsd+2 more6Debian Linux FreebsdHeimdal+3 moreMay 13, 2026 Jul 13, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_tick...Show more |
8Debian FedoraprojectFreebsd+5 more10Debian Linux FedoraFreebsd+7 moreApr 29, 2026 Dec 25, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products a...Show more |
2Debian Heimdal Project2Debian Linux HeimdalApr 16, 2026 Jul 7, 2004 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow. |