Mit
mit
159 CVEs • 10 products
Products (10)
Click to collapseToggle
Products (10)
Click to collapse
CVEs (159)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech....Show more |
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote...Show more |
2Debian Mit2Debian Linux Kerberos 5Jun 17, 2026 Jun 28, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields. |
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application. |
2Mit Netapp8Active Iq Unified Manager Cloud Volumes Ontap MediatorH610c Firmware+5 moreJun 17, 2026 Feb 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. |
2Mit Netapp9Active Iq Unified Manager Cloud Volumes Ontap MediatorH610c Firmware+6 moreJun 17, 2026 Feb 29, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
2Mit Netapp9Active Iq Unified Manager Cloud Volumes Ontap MediatorH610c Firmware+6 moreJun 17, 2026 Feb 29, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. |
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket t...Show more |
3Debian MitNetapp7Active Iq Unified Manager Clustered Data OntapDebian Linux+4 moreJun 17, 2026 Aug 7, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_princip...Show more |
3Heimdal Project MitSamba3Heimdal Kerberos 5SambaJun 17, 2026 Dec 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms...Show more |
4Debian GnuMit+1 more4Debian Linux InetutilsKerberos 5+1 moreJun 17, 2026 Aug 30, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the te...Show more |
A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted sb3 file. |
5Debian FedoraprojectMit+2 more5Communications Cloud Native Core Network Slice Selection Function Debian LinuxFedora+2 moreJun 17, 2026 Aug 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field. |
4Debian MitNetapp+1 more7Active Iq Unified Manager Debian LinuxKerberos 5+4 moreJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. Thi...Show more |
Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may have an unexpected loca...Show more |
In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifyi...Show more |
An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the rcp client only pe...Show more |
4Fedoraproject MitNetapp+1 more11Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Nov 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recurs...Show more |
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMe...Show more |
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code execution because the URL's c...Show more |