Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 5.6% | — | MIT Kerberos 5 | 28/9/2004 | 16/6/2026 | The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding. | |
| Modificada | Media (4.6) | 8.9% | — | MIT Kerberos 5Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 28/9/2004 | 16/6/2026 | Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code. | |
| Modificada | Alta (10) | 12% | — | MIT KerberosMIT Kerberos 5SGI PropackSUN Seam+3 | 18/8/2004 | 16/6/2026 | Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root. | |
| Modificada | Media (5) | 1.9% | — | MIT KerberosMIT Kerberos 5 | 2/4/2003 | 16/6/2026 | The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun"). | |
| Modificada | Media (5) | 2.7% | — | MIT KerberosMIT Kerberos 5 | 2/4/2003 | 16/6/2026 | The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun"). | |
| Modificada | Alta (7.5) | 15% | — | GNU GlibcMIT Kerberos 5OpenafsSGI Irix+9 | 25/3/2003 | 16/6/2026 | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability… | |
| Modificada | Alta (7.5) | 4.3% | — | MIT Kerberos | 24/3/2003 | 16/6/2026 | Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing." | |
| Modificada | Alta (7.5) | 4.3% | — | MIT Kerberos | 24/3/2003 | 16/6/2026 | Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack. | |
| Modificada | Media (5) | 4.5% | — | MIT Kerberos 5 | 19/2/2003 | 16/6/2026 | Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value. | |
| Modificada | Alta (7.5) | 3.6% | — | MIT Kerberos 5 | 19/2/2003 | 16/6/2026 | Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys. | |
| Modificada | Media (5) | 4.8% | — | MIT Kerberos 5SUN Enterprise Authentication MechanismSUN SolarisSunos | 19/2/2003 | 16/6/2026 | MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference. | |
| Modificada | Alta (10) | 3.5% | — | MIT Kerberos FTP ClientRedhat LinuxMandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake Linux | 19/2/2003 | 16/6/2026 | Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client. | |
| Modificada | Alta (7.5) | 5.6% | — | MIT Kerberos 5 | 19/2/2003 | 16/6/2026 | Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names. | |
| Modificada | Alta (10) | 15% | — | KTH Kerberos 4KTH Kerberos 5MIT Kerberos 5Debian Linux | 4/11/2002 | 16/6/2026 | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly… | |
| Modificada | Alta (7.5) | 2.4% | — | KTH KerberosLuke Mewburn Lukemftp | 18/6/2002 | 16/6/2026 | Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request. | |
| Modificada | Media (5) | 1.1% | — | KTH Kerberos | 27/8/2001 | 16/6/2026 | KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 1.3% | — | KTH Kerberos | 27/8/2001 | 16/6/2026 | The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack. | |
| Modificada | Alta (10) | 39% | 💥 Exploit | MIT KerberosMIT Kerberos 5Linux NetkitSGI Irix+7 | 14/8/2001 | 16/6/2026 | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. | |
| Modificada | Baja (2.1) | 0.41% | — | MIT KerberosMIT Kerberos 5 | 27/6/2001 | 16/6/2026 | Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files. | |
| Modificada | Alta (10) | 19% | 💥 Exploit | MIT Kerberos 5SGI IrixFreebsdNetbsd+1 | 18/6/2001 | 16/6/2026 | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3. | |
| Modificada | Alta (7.5) | 4.0% | — | MIT Kerberos 5 | 16/5/2001 | 16/6/2026 | Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function. | |
| Modificada | Alta (7.2) | 0.48% | — | KTH KerberosNetbsd | 16/2/2001 | 16/6/2026 | KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges. | |
| Modificada | Alta (7.2) | 0.96% | 💥 Exploit | KTH Kerberos | 16/2/2001 | 16/6/2026 | KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges. | |
| Modificada | Alta (7.2) | 2.5% | — | KTH Kerberos | 16/2/2001 | 16/6/2026 | Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request. | |
| Modificada | Baja (1.2) | 0.45% | — | KTH Kerberos | 16/2/2001 | 16/6/2026 | KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file. |