Show filters
156 Total Results
Displaying 111-120 of 156
Sort by:
Attacker Value
Unknown
CVE-2005-1174
Disclosure Date: July 18, 2005 (last updated February 22, 2025)
MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.
0
Attacker Value
Unknown
CVE-2005-0488
Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
0
Attacker Value
Unknown
CVE-2004-0971
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2004-1189
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2004-0772
Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0643
Disclosure Date: September 28, 2004 (last updated February 22, 2025)
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0642
Disclosure Date: September 28, 2004 (last updated February 22, 2025)
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0644
Disclosure Date: September 28, 2004 (last updated February 22, 2025)
The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.
0
Attacker Value
Unknown
CVE-2004-0523
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
0
Attacker Value
Unknown
CVE-2003-0072
Disclosure Date: April 02, 2003 (last updated February 22, 2025)
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").
0