Show filters
156 Total Results
Displaying 121-130 of 156
Sort by:
Attacker Value
Unknown
CVE-2003-0082
Disclosure Date: April 02, 2003 (last updated February 22, 2025)
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").
0
Attacker Value
Unknown
CVE-2003-0028
Disclosure Date: March 25, 2003 (last updated February 22, 2025)
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
0
Attacker Value
Unknown
CVE-2003-0138
Disclosure Date: March 24, 2003 (last updated February 22, 2025)
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.
0
Attacker Value
Unknown
CVE-2003-0139
Disclosure Date: March 24, 2003 (last updated February 22, 2025)
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."
0
Attacker Value
Unknown
CVE-2003-0059
Disclosure Date: February 19, 2003 (last updated February 22, 2025)
Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.
0
Attacker Value
Unknown
CVE-2003-0058
Disclosure Date: February 19, 2003 (last updated February 22, 2025)
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
0
Attacker Value
Unknown
CVE-2003-0041
Disclosure Date: February 19, 2003 (last updated February 22, 2025)
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
0
Attacker Value
Unknown
CVE-2002-0036
Disclosure Date: February 19, 2003 (last updated February 22, 2025)
Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.
0
Attacker Value
Unknown
CVE-2003-0060
Disclosure Date: February 19, 2003 (last updated February 22, 2025)
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.
0
Attacker Value
Unknown
CVE-2002-1235
Disclosure Date: November 04, 2002 (last updated February 22, 2025)
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
0