MIT records
159 published records for vendor mit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.6%
- Pre-auth RCE
- 32
- With a fix record
- 83%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference14
- CWE-20 Improper Input Validation13
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-415 Double Free8
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-399 Resource Management Errors6
The weakness classes this vendor ships most often: where to look.
CWEAll records
159 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2011-4862Weaponized | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Critical10.0 | — | 95.0% | Dec 24, 2011 |
52Plan | CVE-2001-0554Proof of concept | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Critical10.0 | — | 38.7% | Aug 14, 2001 |
49Plan | CVE-2007-0956No exploit | The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username mit · kerberos 5 · CWE-306 | Critical10.0 | — | 29.8% | Apr 5, 2007 |
46Plan | CVE-2011-0285Proof of concept | The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 mit · kerberos 5 · CWE-20 | Critical10.0 | — | 20.8% | Apr 14, 2011 |
46Plan | CVE-2001-0247Proof of concept | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Critical10.0 | — | 19.3% | Jun 18, 2001 |
45Plan | CVE-2000-0389Proof of concept | Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.cygnus · cygnus network security | Critical10.0 | — | 16.5% | May 16, 2000 |
45Plan | CVE-2002-1235No exploit | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and eamit · kerberos 5 | Critical10.0 | — | 15.1% | Nov 4, 2002 |
43Plan | CVE-2004-0523No exploit | Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrarymit · kerberos | Critical10.0 | — | 11.7% | Aug 18, 2004 |
43Plan | CVE-2007-2442No exploit | The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute armit · kerberos 5 · CWE-824 | Critical10.0 | — | 11.4% | Jun 26, 2007 |
43Plan | CVE-2007-3999No exploit | Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in Mmit · kerberos 5 · CWE-119 | Critical10.0 | — | 11.0% | Sep 5, 2007 |
43Plan | CVE-2009-0846No exploit | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) beformit · kerberos 5 · CWE-824 | Critical10.0 | — | 8.9% | Apr 8, 2009 |
43Plan | CVE-2008-0947No exploit | Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execumit · kerberos 5 · CWE-119 | Critical10.0 | — | 8.8% | Mar 18, 2008 |
42Plan | CVE-2005-1689No exploit | Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrmit · kerberos 5 · CWE-415 | Critical9.8 | — | 11.0% | Jul 18, 2005 |
42Plan | CVE-2008-0062No exploit | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial mit · kerberos 5 · CWE-665 | Critical9.8 | — | 10.1% | Mar 19, 2008 |
42Plan | CVE-2009-4212No exploit | Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 throumit · kerberos · CWE-189 | Critical10.0 | — | 7.6% | Jan 13, 2010 |
42Plan | CVE-2007-5902No exploit | Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to havmit · kerberos 5 · CWE-189 | Critical10.0 | — | 5.9% | Dec 5, 2007 |
41Plan | CVE-2017-15088No exploit | plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which mit · kerberos 5 · CWE-121 | Critical9.8 | — | 8.3% | Nov 23, 2017 |
41Plan | CVE-2004-0772No exploit | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Critical9.8 | — | 7.0% | Oct 20, 2004 |
41Plan | CVE-2017-11462No exploit | Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion mit · kerberos 5 · CWE-415 | Critical9.8 | — | 5.5% | Sep 13, 2017 |
41Plan | CVE-2007-4743No exploit | The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by mit · kerberos 5 · CWE-119 | Critical10.0 | — | 4.6% | Sep 6, 2007 |
41Plan | CVE-2000-0391No exploit | Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.cygnus · cygnus network security | Critical10.0 | — | 4.0% | May 16, 2000 |
41Plan | CVE-2000-0390No exploit | Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.cygnus · cygnus network security | Critical10.0 | — | 4.0% | May 16, 2000 |
41Plan | CVE-2003-0041No exploit | Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the clientmit · kerberos ftp client · CWE-78 | Critical10.0 | — | 3.5% | Feb 19, 2003 |
41Plan | CVE-2000-0514No exploit | GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a deniamit · kerberos 5 | Critical10.0 | — | 2.5% | Jun 14, 2000 |
40Plan | CVE-2020-7750Proof of concept | Cross-site Scripting (XSS)mit · scratch-svg-renderer · CWE-79 | Critical9.6 | — | 6.1% | Oct 21, 2020 |
- CVE-2011-486268This week
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
CriticalCVSS 10.0WeaponizedEPSS 95%mit · krb5-applDec 24, 2011
- CVE-2001-055452Plan
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
CriticalCVSS 10.0Proof of conceptEPSS 39%mit · kerberosAug 14, 2001
- CVE-2007-095649Plan
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username
CriticalCVSS 10.0No exploitEPSS 30%mit · kerberos 5Apr 5, 2007
- CVE-2011-028546Plan
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9
CriticalCVSS 10.0Proof of conceptEPSS 21%mit · kerberos 5Apr 14, 2011
- CVE-2001-024746Plan
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
CriticalCVSS 10.0Proof of conceptEPSS 19%mit · kerberos 5Jun 18, 2001
- CVE-2000-038945Plan
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
CriticalCVSS 10.0Proof of conceptEPSS 17%cygnus · cygnus network securityMay 16, 2000
- CVE-2002-123545Plan
The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and ea
CriticalCVSS 10.0No exploitEPSS 15%mit · kerberos 5Nov 4, 2002
- CVE-2004-052343Plan
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary
CriticalCVSS 10.0No exploitEPSS 12%mit · kerberosAug 18, 2004
- CVE-2007-244243Plan
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute ar
CriticalCVSS 10.0No exploitEPSS 11%mit · kerberos 5Jun 26, 2007
- CVE-2007-399943Plan
Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in M
CriticalCVSS 10.0No exploitEPSS 11%mit · kerberos 5Sep 5, 2007
- CVE-2009-084643Plan
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) befor
CriticalCVSS 10.0No exploitEPSS 9%mit · kerberos 5Apr 8, 2009
- CVE-2008-094743Plan
Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execu
CriticalCVSS 10.0No exploitEPSS 9%mit · kerberos 5Mar 18, 2008
- CVE-2005-168942Plan
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr
CriticalCVSS 9.8No exploitEPSS 11%mit · kerberos 5Jul 18, 2005
- CVE-2008-006242Plan
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial
CriticalCVSS 9.8No exploitEPSS 10%mit · kerberos 5Mar 19, 2008
- CVE-2009-421242Plan
Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 throu
CriticalCVSS 10.0No exploitEPSS 8%mit · kerberosJan 13, 2010
- CVE-2007-590242Plan
Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to hav
CriticalCVSS 10.0No exploitEPSS 6%mit · kerberos 5Dec 5, 2007
- CVE-2017-1508841Plan
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which
CriticalCVSS 9.8No exploitEPSS 8%mit · kerberos 5Nov 23, 2017
- CVE-2004-077241Plan
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
CriticalCVSS 9.8No exploitEPSS 7%mit · kerberos 5Oct 20, 2004
- CVE-2017-1146241Plan
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion
CriticalCVSS 9.8No exploitEPSS 5%mit · kerberos 5Sep 13, 2017
- CVE-2007-474341Plan
The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by
CriticalCVSS 10.0No exploitEPSS 5%mit · kerberos 5Sep 6, 2007
- CVE-2000-039141Plan
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
CriticalCVSS 10.0No exploitEPSS 4%cygnus · cygnus network securityMay 16, 2000
- CVE-2000-039041Plan
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
CriticalCVSS 10.0No exploitEPSS 4%cygnus · cygnus network securityMay 16, 2000
- CVE-2003-004141Plan
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client
CriticalCVSS 10.0No exploitEPSS 4%mit · kerberos ftp clientFeb 19, 2003
- CVE-2000-051441Plan
GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denia
CriticalCVSS 10.0No exploitEPSS 3%mit · kerberos 5Jun 14, 2000
- CVE-2020-775040Plan
Cross-site Scripting (XSS)
CriticalCVSS 9.6Proof of conceptEPSS 6%mit · scratch-svg-rendererOct 21, 2020