Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2009-0846
Disclosure Date: April 09, 2009 (last updated February 09, 2024)
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
0
Attacker Value
Unknown
CVE-2008-0063
Disclosure Date: March 19, 2008 (last updated February 09, 2024)
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
0
Attacker Value
Unknown
CVE-2008-0062
Disclosure Date: March 19, 2008 (last updated December 29, 2023)
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.
0
Attacker Value
Unknown
CVE-2007-2443
Disclosure Date: June 26, 2007 (last updated October 04, 2023)
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
0
Attacker Value
Unknown
CVE-2007-2798
Disclosure Date: June 26, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
0
Attacker Value
Unknown
CVE-2007-2442
Disclosure Date: June 26, 2007 (last updated October 04, 2023)
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.
0
Attacker Value
Unknown
CVE-2007-1216
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".
0
Attacker Value
Unknown
CVE-2007-0957
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.
0
Attacker Value
Unknown
CVE-2007-0956
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
0
Attacker Value
Unknown
CVE-2003-0028
Disclosure Date: March 25, 2003 (last updated February 22, 2025)
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
0