Skip to content
Noroxi

MIT records

159 published records for vendor mit.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.6%
Pre-auth RCE
32
With a fix record
83%
Median publish → KEV
No record has entered KEV

All records

159 records
  • CVE-2011-4862
    68This week

    Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and

    CriticalCVSS 10.0WeaponizedEPSS 95%

    mit · krb5-applDec 24, 2011

  • Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a

    CriticalCVSS 10.0Proof of conceptEPSS 39%

    mit · kerberosAug 14, 2001

  • The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username

    CriticalCVSS 10.0No exploitEPSS 30%

    mit · kerberos 5Apr 5, 2007

  • The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9

    CriticalCVSS 10.0Proof of conceptEPSS 21%

    mit · kerberos 5Apr 14, 2011

  • Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se

    CriticalCVSS 10.0Proof of conceptEPSS 19%

    mit · kerberos 5Jun 18, 2001

  • Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.

    CriticalCVSS 10.0Proof of conceptEPSS 17%

    cygnus · cygnus network securityMay 16, 2000

  • The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and ea

    CriticalCVSS 10.0No exploitEPSS 15%

    mit · kerberos 5Nov 4, 2002

  • Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary

    CriticalCVSS 10.0No exploitEPSS 12%

    mit · kerberosAug 18, 2004

  • The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute ar

    CriticalCVSS 10.0No exploitEPSS 11%

    mit · kerberos 5Jun 26, 2007

  • Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in M

    CriticalCVSS 10.0No exploitEPSS 11%

    mit · kerberos 5Sep 5, 2007

  • The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) befor

    CriticalCVSS 10.0No exploitEPSS 9%

    mit · kerberos 5Apr 8, 2009

  • Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execu

    CriticalCVSS 10.0No exploitEPSS 9%

    mit · kerberos 5Mar 18, 2008

  • Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr

    CriticalCVSS 9.8No exploitEPSS 11%

    mit · kerberos 5Jul 18, 2005

  • KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial

    CriticalCVSS 9.8No exploitEPSS 10%

    mit · kerberos 5Mar 19, 2008

  • Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 throu

    CriticalCVSS 10.0No exploitEPSS 8%

    mit · kerberosJan 13, 2010

  • Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to hav

    CriticalCVSS 10.0No exploitEPSS 6%

    mit · kerberos 5Dec 5, 2007

  • plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which

    CriticalCVSS 9.8No exploitEPSS 8%

    mit · kerberos 5Nov 23, 2017

  • Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec

    CriticalCVSS 9.8No exploitEPSS 7%

    mit · kerberos 5Oct 20, 2004

  • Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion

    CriticalCVSS 9.8No exploitEPSS 5%

    mit · kerberos 5Sep 13, 2017

  • The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by

    CriticalCVSS 10.0No exploitEPSS 5%

    mit · kerberos 5Sep 6, 2007

  • Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.

    CriticalCVSS 10.0No exploitEPSS 4%

    cygnus · cygnus network securityMay 16, 2000

  • Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.

    CriticalCVSS 10.0No exploitEPSS 4%

    cygnus · cygnus network securityMay 16, 2000

  • Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client

    CriticalCVSS 10.0No exploitEPSS 4%

    mit · kerberos ftp clientFeb 19, 2003

  • GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denia

    CriticalCVSS 10.0No exploitEPSS 3%

    mit · kerberos 5Jun 14, 2000

  • Cross-site Scripting (XSS)

    CriticalCVSS 9.6Proof of conceptEPSS 6%

    mit · scratch-svg-rendererOct 21, 2020