← Back

Mit

mit

159 CVEs • 10 products

Products (10)

Click to collapse
Toggle

CVEs (159)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mit
1Kerberos 5
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
1Mit
1Kerberos 5
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number o...Show more
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.Show less
3Debian
MitOpenpkg
3Debian Linux
Kerberos 5Openpkg
Apr 16, 2026
Oct 20, 2004
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.
1Mit
1Kerberos 5
Apr 16, 2026
Sep 28, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.
3Debian
MitRedhat
5Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 16, 2026
Sep 28, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
3Debian
MitRedhat
5Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 16, 2026
Sep 28, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to...Show more
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.Show less
4Mit
SgiSun+1 more
7Kerberos
Kerberos 5Propack+4 more
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
1Mit
1Cgiemail
Apr 16, 2026
Mar 3, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header...Show more
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.Show less
1Mit
2Kerberos
Kerberos 5
Apr 16, 2026
Apr 2, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that cau...Show more
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").Show less
1Mit
2Kerberos
Kerberos 5
Apr 16, 2026
Apr 2, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that cau...Show more
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").Show less
10Cray
FreebsdGnu+7 more
13Aix
FreebsdGlibc+10 more
Apr 16, 2026
Mar 25, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers...Show more
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.Show less
1Mit
1Kerberos
Apr 16, 2026
Mar 24, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorize...Show more
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."Show less
1Mit
1Kerberos
Apr 16, 2026
Mar 24, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.
1Mit
1Kerberos 5
Apr 16, 2026
Feb 19, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for...Show more
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.Show less
1Mit
1Kerberos 5
Apr 16, 2026
Feb 19, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.
2Mit
Sun
4Enterprise Authentication Mechanism
Kerberos 5Solaris+1 more
Apr 16, 2026
Feb 19, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null derefe...Show more
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.Show less
3Mandrakesoft
MitRedhat
4Kerberos Ftp Client
LinuxMandrake Linux+1 more
Apr 16, 2026
Feb 19, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
1Mit
1Kerberos 5
Apr 16, 2026
Feb 19, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.
1Mit
1Cgiemail
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter.
3Debian
KthMit
4Debian Linux
Kerberos 5Kth Kerberos 4+1 more
Apr 16, 2026
Nov 4, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in K...Show more
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.Show less