Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.4% | — | MIT KerberosMIT Kerberos 5 | 22/2/2010 | 16/6/2026 | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request. | |
| Modificada | Alta (10) | 7.6% | — | MIT KerberosMIT Kerberos 5 | 13/1/2010 | 16/6/2026 | Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is… | |
| Modificada | Media (5) | 40% | — | MIT Kerberos 5 | 29/12/2009 | 16/6/2026 | The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request. | |
| Modificada | Alta (10) | 8.9% | — | MIT Kerberos 5Fedoraproject FedoraCanonical Ubuntu LinuxApple MAC OS X+5 | 9/4/2009 | 16/6/2026 | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free… | |
| Modificada | Media (5.8) | 4.3% | — | MIT KerberosMIT Kerberos 5 | 9/4/2009 | 16/6/2026 | The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read. | |
| Modificada | Media (5) | 5.6% | — | MIT KerberosMIT Kerberos 5 | 27/3/2009 | 16/6/2026 | The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token. | |
| Modificada | Alta (7.5) | 3.5% | — | MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerOpensuse+7 | 19/3/2008 | 16/6/2026 | The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values." | |
| Modificada | Crítica (9.8) | 10% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu LinuxFedoraproject Fedora | 19/3/2008 | 16/6/2026 | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free. | |
| Modificada | Alta (9.3) | 7.3% | — | MIT Kerberos 5 | 19/3/2008 | 16/6/2026 | Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly… | |
| Modificada | Alta (10) | 8.8% | — | MIT Kerberos 5 | 19/3/2008 | 16/6/2026 | Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors. | |
| Modificada | Alta (9.3) | 2.7% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is… | |
| Modificada | Media (6.9) | 0.47% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code. | |
| Modificada | Alta (9) | 2.7% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NOTE: the free operations occur in code that stores the krb5kdc master key, and so the attacker must have privileges to store this key. | |
| Modificada | Alta (10) | 5.9% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request. | |
| Modificada | Media (6.9) | 0.37% | — | MIT Kerberos 5 | 6/12/2007 | 16/6/2026 | Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 4.6% | — | MIT Kerberos 5 | 6/9/2007 | 16/6/2026 | The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might… | |
| Modificada | Alta (10) | 11% | — | MIT Kerberos 5 | 5/9/2007 | 16/6/2026 | Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a… | |
| Modificada | Alta (8.5) | 6.1% | — | MIT Kerberos 5Fedoraproject Fedora | 5/9/2007 | 16/6/2026 | The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to… | |
| Modificada | Alta (8.3) | 3.5% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu Linux | 26/6/2007 | 16/6/2026 | Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value. | |
| Modificada | Alta (10) | 11% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu Linux | 26/6/2007 | 16/6/2026 | The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup. | |
| Modificada | Alta (9) | 7.5% | — | MIT Kerberos 5Canonical Ubuntu LinuxDebian Linux | 26/6/2007 | 16/6/2026 | Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal. | |
| Modificada | Alta (7.2) | 0.36% | — | MIT Kerberos 5Todd Miller Sudo | 11/6/2007 | 16/6/2026 | sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this… | |
| Modificada | Alta (10) | 30% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu Linux | 6/4/2007 | 16/6/2026 | The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882. | |
| Modificada | Alta (9) | 9.9% | — | MIT Kerberos 5Canonical Ubuntu LinuxDebian Linux | 6/4/2007 | 16/6/2026 | Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the… | |
| Modificada | Alta (9) | 10% | — | MIT Kerberos 5Debian LinuxCanonical Ubuntu Linux | 6/4/2007 | 16/6/2026 | Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments,… |