KTH
KTH Kerberos: vulnerabilidades y CVE
KTH Kerberos tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2002-0600 | Alta (7.5) | 2.4% | — | 18 jun 2002 | Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request. |
| CVE-2001-1443 | Media (5) | 1.1% | — | 27 ago 2001 | KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a… |
| CVE-2001-1444 | Alta (7.5) | 1.3% | — | 27 ago 2001 | The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade… |
| CVE-2001-0035 | Alta (7.2) | 2.5% | — | 16 feb 2001 | Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request. |
| CVE-2001-0033 | Alta (7.2) | 0.48% | — | 16 feb 2001 | KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows… |
| CVE-2001-0034 | Alta (7.2) | 0.96% | — | 16 feb 2001 | KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges. |
| CVE-2001-0036 | Baja (1.2) | 0.45% | — | 16 feb 2001 | KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file. |
| CVE-1999-1099 | Media (5) | 1.3% | — | 22 nov 1996 | Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user. |