Show filters
139 Total Results
Displaying 101-110 of 139
Sort by:
Attacker Value
Unknown
CVE-2006-3083
Disclosure Date: August 09, 2006 (last updated October 04, 2023)
The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.
0
Attacker Value
Unknown
CVE-2005-1175
Disclosure Date: July 18, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.
0
Attacker Value
Unknown
CVE-2005-1689
Disclosure Date: July 18, 2005 (last updated February 22, 2025)
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
0
Attacker Value
Unknown
CVE-2005-1174
Disclosure Date: July 18, 2005 (last updated February 22, 2025)
MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.
0
Attacker Value
Unknown
CVE-2005-0488
Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
0
Attacker Value
Unknown
CVE-2004-0971
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2004-1189
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2004-0772
Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0643
Disclosure Date: September 28, 2004 (last updated February 22, 2025)
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0642
Disclosure Date: September 28, 2004 (last updated February 22, 2025)
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.
0