Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2006-6143
Disclosure Date: December 31, 2006 (last updated February 09, 2024)
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-3084
Disclosure Date: August 09, 2006 (last updated October 04, 2023)
The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE: as of 20060808, it is not known whether an exploitable attack scenario exists for these issues.
0
Attacker Value
Unknown
CVE-2006-3083
Disclosure Date: August 09, 2006 (last updated October 04, 2023)
The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.
0
Attacker Value
Unknown
CVE-2001-0554
Disclosure Date: August 14, 2001 (last updated February 22, 2025)
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
0
Attacker Value
Unknown
CVE-2001-0417
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
0
Attacker Value
Unknown
CVE-2001-0247
Disclosure Date: June 18, 2001 (last updated February 22, 2025)
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
0
Attacker Value
Unknown
CVE-1999-1296
Disclosure Date: April 29, 1997 (last updated February 22, 2025)
Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.
0