Записи MIT
159 опубликованных записей вендора mit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,6 %
- Pre-auth RCE
- 32
- С записью об исправлении
- 83 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference14
- CWE-20 Improper Input Validation13
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-415 Double Free8
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-399 Resource Management Errors6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
159 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2011-4862Готовый эксплойт | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Критическая10,0 | — | 95,0 % | 24 дек. 2011 г. |
52В плане | CVE-2001-0554Proof of concept | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Критическая10,0 | — | 38,7 % | 14 авг. 2001 г. |
49В плане | CVE-2007-0956Эксплойта нет | The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username mit · kerberos 5 · CWE-306 | Критическая10,0 | — | 29,8 % | 5 апр. 2007 г. |
46В плане | CVE-2011-0285Proof of concept | The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 mit · kerberos 5 · CWE-20 | Критическая10,0 | — | 20,8 % | 14 апр. 2011 г. |
46В плане | CVE-2001-0247Proof of concept | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Критическая10,0 | — | 19,3 % | 18 июн. 2001 г. |
45В плане | CVE-2000-0389Proof of concept | Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.cygnus · cygnus network security | Критическая10,0 | — | 16,5 % | 16 мая 2000 г. |
45В плане | CVE-2002-1235Эксплойта нет | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and eamit · kerberos 5 | Критическая10,0 | — | 15,1 % | 4 нояб. 2002 г. |
43В плане | CVE-2004-0523Эксплойта нет | Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrarymit · kerberos | Критическая10,0 | — | 11,7 % | 18 авг. 2004 г. |
43В плане | CVE-2007-2442Эксплойта нет | The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute armit · kerberos 5 · CWE-824 | Критическая10,0 | — | 11,4 % | 26 июн. 2007 г. |
43В плане | CVE-2007-3999Эксплойта нет | Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in Mmit · kerberos 5 · CWE-119 | Критическая10,0 | — | 11,0 % | 5 сент. 2007 г. |
43В плане | CVE-2009-0846Эксплойта нет | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) beformit · kerberos 5 · CWE-824 | Критическая10,0 | — | 8,9 % | 8 апр. 2009 г. |
43В плане | CVE-2008-0947Эксплойта нет | Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execumit · kerberos 5 · CWE-119 | Критическая10,0 | — | 8,8 % | 18 мар. 2008 г. |
42В плане | CVE-2005-1689Эксплойта нет | Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrmit · kerberos 5 · CWE-415 | Критическая9,8 | — | 11,0 % | 18 июл. 2005 г. |
42В плане | CVE-2008-0062Эксплойта нет | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial mit · kerberos 5 · CWE-665 | Критическая9,8 | — | 10,1 % | 19 мар. 2008 г. |
42В плане | CVE-2009-4212Эксплойта нет | Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 throumit · kerberos · CWE-189 | Критическая10,0 | — | 7,6 % | 13 янв. 2010 г. |
42В плане | CVE-2007-5902Эксплойта нет | Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to havmit · kerberos 5 · CWE-189 | Критическая10,0 | — | 5,9 % | 5 дек. 2007 г. |
41В плане | CVE-2017-15088Эксплойта нет | plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which mit · kerberos 5 · CWE-121 | Критическая9,8 | — | 8,3 % | 23 нояб. 2017 г. |
41В плане | CVE-2004-0772Эксплойта нет | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Критическая9,8 | — | 7,0 % | 20 окт. 2004 г. |
41В плане | CVE-2017-11462Эксплойта нет | Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion mit · kerberos 5 · CWE-415 | Критическая9,8 | — | 5,5 % | 13 сент. 2017 г. |
41В плане | CVE-2007-4743Эксплойта нет | The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by mit · kerberos 5 · CWE-119 | Критическая10,0 | — | 4,6 % | 6 сент. 2007 г. |
41В плане | CVE-2000-0391Эксплойта нет | Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.cygnus · cygnus network security | Критическая10,0 | — | 4,0 % | 16 мая 2000 г. |
41В плане | CVE-2000-0390Эксплойта нет | Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.cygnus · cygnus network security | Критическая10,0 | — | 4,0 % | 16 мая 2000 г. |
41В плане | CVE-2003-0041Эксплойта нет | Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the clientmit · kerberos ftp client · CWE-78 | Критическая10,0 | — | 3,5 % | 19 февр. 2003 г. |
41В плане | CVE-2000-0514Эксплойта нет | GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a deniamit · kerberos 5 | Критическая10,0 | — | 2,5 % | 14 июн. 2000 г. |
40В плане | CVE-2020-7750Proof of concept | Cross-site Scripting (XSS)mit · scratch-svg-renderer · CWE-79 | Критическая9,6 | — | 6,1 % | 21 окт. 2020 г. |
- CVE-2011-486268На этой неделе
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %mit · krb5-appl24 дек. 2011 г.
- CVE-2001-055452В плане
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
КритическаяCVSS 10,0Proof of conceptEPSS 39 %mit · kerberos14 авг. 2001 г.
- CVE-2007-095649В плане
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username
КритическаяCVSS 10,0Эксплойта нетEPSS 30 %mit · kerberos 55 апр. 2007 г.
- CVE-2011-028546В плане
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9
КритическаяCVSS 10,0Proof of conceptEPSS 21 %mit · kerberos 514 апр. 2011 г.
- CVE-2001-024746В плане
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
КритическаяCVSS 10,0Proof of conceptEPSS 19 %mit · kerberos 518 июн. 2001 г.
- CVE-2000-038945В плане
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
КритическаяCVSS 10,0Proof of conceptEPSS 17 %cygnus · cygnus network security16 мая 2000 г.
- CVE-2002-123545В плане
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and ea
КритическаяCVSS 10,0Эксплойта нетEPSS 15 %mit · kerberos 54 нояб. 2002 г.
- CVE-2004-052343В плане
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary
КритическаяCVSS 10,0Эксплойта нетEPSS 12 %mit · kerberos18 авг. 2004 г.
- CVE-2007-244243В плане
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute ar
КритическаяCVSS 10,0Эксплойта нетEPSS 11 %mit · kerberos 526 июн. 2007 г.
- CVE-2007-399943В плане
Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in M
КритическаяCVSS 10,0Эксплойта нетEPSS 11 %mit · kerberos 55 сент. 2007 г.
- CVE-2009-084643В плане
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) befor
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %mit · kerberos 58 апр. 2009 г.
- CVE-2008-094743В плане
Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execu
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %mit · kerberos 518 мар. 2008 г.
- CVE-2005-168942В плане
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %mit · kerberos 518 июл. 2005 г.
- CVE-2008-006242В плане
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %mit · kerberos 519 мар. 2008 г.
- CVE-2009-421242В плане
Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 throu
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %mit · kerberos13 янв. 2010 г.
- CVE-2007-590242В плане
Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to hav
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %mit · kerberos 55 дек. 2007 г.
- CVE-2017-1508841В плане
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %mit · kerberos 523 нояб. 2017 г.
- CVE-2004-077241В плане
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %mit · kerberos 520 окт. 2004 г.
- CVE-2017-1146241В плане
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mit · kerberos 513 сент. 2017 г.
- CVE-2007-474341В плане
The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %mit · kerberos 56 сент. 2007 г.
- CVE-2000-039141В плане
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %cygnus · cygnus network security16 мая 2000 г.
- CVE-2000-039041В плане
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %cygnus · cygnus network security16 мая 2000 г.
- CVE-2003-004141В плане
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %mit · kerberos ftp client19 февр. 2003 г.
- CVE-2000-051441В плане
GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denia
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %mit · kerberos 514 июн. 2000 г.
- CVE-2020-775040В плане
Cross-site Scripting (XSS)
КритическаяCVSS 9,6Proof of conceptEPSS 6 %mit · scratch-svg-renderer21 окт. 2020 г.