Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.42%—Kerberos AgentAI20/8/202618/9/2026
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client…
AnalizadaAlta (7.5)0.78%—MIT Kerberos 528/4/20268/7/2026
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in…
ModificadaAlta (7.5)0.79%—MIT Kerberos 528/4/202614/7/2026
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
AplazadaAlta (7.1)0.51%—MIT Kerberos 5AI16/1/202617/6/2026
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
AplazadaAlta (8.8)0.80%—System Security Services Daemon SssdAIMicrosoft Active DirectoryAIMIT KerberosAI9/10/202531/8/2026
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with…
AplazadaMedia (5.9)0.34%—MIT KerberosAI15/4/20251/9/2026
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized…
ModificadaCrítica (9.1)1.9%—MIT Kerberos 5Debian Linux28/6/202417/6/2026
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
ModificadaAlta (7.5)0.75%—MIT Kerberos 528/6/202417/6/2026
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
ModificadaMedia (5.5)0.44%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+429/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
AnalizadaAlta (7.5)1.1%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+529/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
AnalizadaMedia (5.3)0.81%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+529/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
ModificadaMedia (6.1)0.50%—Kantega-sso Kantega Saml SSO Oidc Kerberos Single Sign-on29/12/202317/6/2026
The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Binding is enabled. This affects 4.4.2 through 4.14.8 before 4.14.9, 5.0.0 through 5.11.4 before 5.11.5, and 6.0.0 through 6.19.0 before 6.20.0. The full product names are Kantega SAML SSO OIDC Kerberos…
ModificadaAlta (8.8)1.5%—MIT Kerberos 516/8/202317/6/2026
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
ModificadaMedia (6.5)2.8%—MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+37/8/202317/6/2026
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
ModificadaAlta (8.8)6.2%—MIT Kerberos 5Heimdal Project HeimdalSamba25/12/202217/6/2026
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other…
ModificadaAlta (7.5)2.1%—GNU InetutilsMIT Kerberos 5Debian LinuxNetkit-telnet Project Netkit-telnet30/8/202217/6/2026
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many…
ModificadaMedia (6.5)2.2%—MIT Kerberos 5Fedoraproject FedoraDebian LinuxStarwindsoftware Starwind Virtual SAN+123/8/202117/6/2026
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
ModificadaAlta (7.5)10%—MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Insight+322/7/202117/6/2026
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
ModificadaAlta (7.5)4.4%—MIT Kerberos 5Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+76/11/202017/6/2026
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
ModificadaAlta (7.8)0.74%—Kerberos Project Kerberos16/5/202017/6/2026
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
ModificadaCrítica (9.8)3.6%—Requests-kerberos Project Requests-kerberosDebian Linux15/12/201917/6/2026
python-requests-Kerberos through 0.5 does not handle mutual authentication
ModificadaAlta (7.5)4.4%—MIT Kerberos 5Fedoraproject Fedora26/9/201917/6/2026
A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.
ModificadaMedia (5.3)1.4%—MIT KerberosDebian Linux26/12/201817/6/2026
A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request.
ModificadaMedia (6.5)3.2%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+126/7/201817/6/2026
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.
En análisisBaja (3.8)2.2%—MIT Kerberos 5Fedoraproject FedoraDebian LinuxRedhat Enterprise Linux Desktop+26/3/201817/6/2026
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not…