Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 4.2% | — | MIT KerberosMIT Kerberos 5 | 10/2/2011 | 16/6/2026 | The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as… | |
| Modificada | Media (5) | 3.7% | — | MIT Kerberos 5 | 10/2/2011 | 16/6/2026 | The do_standalone function in the MIT krb5 KDC database propagation daemon (kpropd) in Kerberos 1.7, 1.8, and 1.9, when running in standalone mode, does not properly handle when a worker child process "exits abnormally," which allows remote attackers to cause a denial of service (listening process termination, no new… | |
| Modificada | Baja (2.1) | 2.1% | — | MIT Kerberos 5 | 2/12/2010 | 16/6/2026 | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "KrbFastReq forgery issue." | |
| Modificada | Media (6.3) | 1.9% | — | MIT Kerberos 5 | 2/12/2010 | 16/6/2026 | MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, and possibly gain privileges, by leveraging the small key space that results from certain one-byte stream-cipher… | |
| Modificada | Baja (3.7) | 2.3% | — | MIT Kerberos 5 | 2/12/2010 | 16/6/2026 | MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum… | |
| Modificada | Baja (3.7) | 2.8% | — | MIT KerberosMIT Kerberos 5 | 2/12/2010 | 16/6/2026 | MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums… | |
| Modificada | Media (6.5) | 3.0% | — | MIT Kerberos 5 | 7/10/2010 | 16/6/2026 | The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information,… | |
| Modificada | Media (6.8) | 6.9% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu LinuxOracle Database Server+3 | 19/5/2010 | 16/6/2026 | The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL… | |
| Modificada | Media (4) | 12% | 💥 Exploit | MIT Kerberos 5 | 22/4/2010 | 16/6/2026 | Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation. | |
| Modificada | Media (6.5) | 5.5% | — | MIT Kerberos 5Fedoraproject FedoraOpensuseSuse Linux Enterprise+1 | 7/4/2010 | 16/6/2026 | Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number. | |
| Modificada | Media (5) | 3.3% | — | MIT Kerberos 5 | 25/3/2010 | 16/6/2026 | The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid packet that triggers incorrect… | |
| Modificada | Alta (7.8) | 2.4% | — | MIT KerberosMIT Kerberos 5 | 22/2/2010 | 16/6/2026 | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request. | |
| Modificada | Alta (10) | 7.6% | — | MIT KerberosMIT Kerberos 5 | 13/1/2010 | 16/6/2026 | Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is… | |
| Modificada | Media (5) | 40% | — | MIT Kerberos 5 | 29/12/2009 | 16/6/2026 | The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request. | |
| Modificada | Media (4.3) | 2.8% | — | MIT Kerberos | 9/4/2009 | 16/6/2026 | The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic. | |
| Modificada | Alta (10) | 8.9% | — | MIT Kerberos 5Fedoraproject FedoraCanonical Ubuntu LinuxApple MAC OS X+5 | 9/4/2009 | 16/6/2026 | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free… | |
| Modificada | Media (5.8) | 4.3% | — | MIT KerberosMIT Kerberos 5 | 9/4/2009 | 16/6/2026 | The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read. | |
| Modificada | Media (5) | 5.6% | — | MIT KerberosMIT Kerberos 5 | 27/3/2009 | 16/6/2026 | The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token. | |
| Modificada | Crítica (9.8) | 10% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu LinuxFedoraproject Fedora | 19/3/2008 | 16/6/2026 | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free. | |
| Modificada | Alta (7.5) | 3.5% | — | MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerOpensuse+7 | 19/3/2008 | 16/6/2026 | The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values." | |
| Modificada | Alta (10) | 8.8% | — | MIT Kerberos 5 | 19/3/2008 | 16/6/2026 | Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors. | |
| Modificada | Alta (9.3) | 7.3% | — | MIT Kerberos 5 | 19/3/2008 | 16/6/2026 | Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly… | |
| Modificada | Media (6.9) | 0.47% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code. | |
| Modificada | Alta (10) | 5.9% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request. | |
| Modificada | Alta (9) | 2.7% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NOTE: the free operations occur in code that stores the krb5kdc master key, and so the attacker must have privileges to store this key. |