Skip to content
Noroxi

kth records

16 published records for vendor kth.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
43.8%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    16 records
    • The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and ea

      CriticalCVSS 10.0No exploitEPSS 15%

      mit · kerberos 5Nov 4, 2002

    • Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain ro

      CriticalCVSS 10.0No exploitEPSS 5%

      kth · heimdalOct 28, 2002

    • Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or loca

      CriticalCVSS 10.0No exploitEPSS 2%

      kth · heimdalOct 28, 2002

    • CVE-2006-0677
      32Monitor

      telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server cr

      HighCVSS 7.8No exploitEPSS 3%

      kth · heimdalFeb 14, 2006

    • CVE-2002-0600
      31Monitor

      Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long re

      HighCVSS 7.5No exploitEPSS 2%

      kth · kth kerberosJun 18, 2002

    • CVE-2012-6303
      30Monitor

      Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4,

      MediumCVSS 6.8Proof of conceptEPSS 10%

      kth · snack sound toolkitOct 28, 2013

    • CVE-2001-1444
      30Monitor

      The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption opt

      HighCVSS 7.5No exploitEPSS 1%

      kth · kth kerberosAug 27, 2001

    • CVE-2001-0035
      29Monitor

      Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execut

      HighCVSS 7.2No exploitEPSS 2%

      kth · kth kerberosFeb 16, 2001

    • CVE-2001-0034
      28Monitor

      KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false prox

      HighCVSS 7.2Proof of conceptEPSS 1%

      kth · kth kerberosFeb 16, 2001

    • CVE-2001-0033
      28Monitor

      KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an altern

      HighCVSS 7.2No exploitEPSS 0%

      kth · kth kerberosFeb 16, 2001

    • CVE-2002-0754
      28Monitor

      Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which coul

      HighCVSS 7.2No exploitEPSS 0%

      freebsd · heimdalAug 12, 2002

    • CVE-2004-0371
      20Monitor

      Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allow

      MediumCVSS 5.0No exploitEPSS 2%

      kth · heimdalMay 4, 2004

    • CVE-1999-1099
      20Monitor

      Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadverten

      MediumCVSS 5.0No exploitEPSS 1%

      kth · kth kerberosNov 22, 1996

    • CVE-2001-1443
      20Monitor

      KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encrypti

      MediumCVSS 5.0No exploitEPSS 1%

      kth · kth kerberosAug 27, 2001

    • Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers

      LowCVSS 2.1No exploitEPSS 0%

      kth · heimdalFeb 7, 2006

    • KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.

      LowCVSS 1.2No exploitEPSS 0%

      kth · kth kerberosFeb 16, 2001