Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)2.5%—MIT Kerberos 514/6/200016/6/2026
GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.
ModificadaMedia (5)2.9%—Cygnus Network Security Project Cygnus Network SecurityKerbnet Project KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.
ModificadaMedia (5)2.9%—Cygnus Network Security Project Cygnus Network SecurityKerbnet Project KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.
ModificadaMedia (5)2.3%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.
ModificadaMedia (5)2.9%—Cygnus Network Security Project Cygnus Network SecurityKerbnet Project KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.
ModificadaMedia (5)2.4%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.
ModificadaAlta (10)4.0%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
ModificadaAlta (7.2)0.44%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.
ModificadaAlta (10)4.0%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
ModificadaAlta (10)17%💥 ExploitCygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
ModificadaAlta (7.2)0.34%—CDEMIT Kerberos 5Transarc AFSDigital Unix11/6/199916/6/2026
The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.
ModificadaAlta (7.5)2.0%—MIT Kerberos5/11/199816/6/2026
Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.
ModificadaAlta (7.2)0.34%—MIT Kerberos 529/4/199716/6/2026
Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.
ModificadaMedia (5)1.3%—KTH Kerberos22/11/199616/6/2026
Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.
ModificadaMedia (4.6)0.39%—MIT KerberosMIT Kerberos 5Process Software MultinetSunos21/2/199616/6/2026
Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.