Heimdal
Heimdal Project · 16 CVEs
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network ac…
Mar 27, 2023
samba: fix introduced a logic inversion
Mar 6, 2023
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_typ…
Dec 26, 2022
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec us…
Dec 25, 2022
krb5: integer overflow vulnerabilities in PAC parsing
Dec 25, 2022
Read one byte past a buffer when normalizing Unicode
Nov 15, 2022
samba: S4U2Self with unkeyed checksum
Jul 31, 2019
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-…
May 15, 2019
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet cont…
Dec 6, 2017
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mec…
Aug 28, 2017
krb5: Metadata taken from the unauthenticated plaintext
Jul 13, 2017
krb5: telnet client and server encrypt_keyid heap-based buffer overflow
Dec 25, 2011
The gss_userok function in appl/ftp/ftpd/gss_userok.c in Heimdal 0.7.2 does not allocate memory for the ticketfile poin…
Dec 6, 2007
The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2…
Aug 9, 2006
security flaw
Aug 9, 2006
k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility adminis…
May 12, 2004
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-3116 | The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on t… | HIGH | 0.89% | Mar 27, 2023 |
| CVE-2022-45142 | samba: fix introduced a logic inversion | HIGH | 0.49% | Mar 6, 2023 |
| CVE-2021-44758 | Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_… | HIGH | 1.28% | Dec 26, 2022 |
| CVE-2022-44640 | Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). | CRITICAL | 2.26% | Dec 25, 2022 |
| CVE-2022-42898 | krb5: integer overflow vulnerabilities in PAC parsing | HIGH | 6.47% | Dec 25, 2022 |
| CVE-2022-41916 | Read one byte past a buffer when normalizing Unicode | HIGH | 0.97% | Nov 15, 2022 |
| CVE-2018-16860 | samba: S4U2Self with unkeyed checksum | HIGH | 2.49% | Jul 31, 2019 |
| CVE-2019-12098 | In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in k… | HIGH | 1.97% | May 15, 2019 |
| CVE-2017-17439 | In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name… | HIGH | 3.43% | Dec 6, 2017 |
| CVE-2017-6594 | The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the… | HIGH | 1.76% | Aug 28, 2017 |
| CVE-2017-11103 | krb5: Metadata taken from the unauthenticated plaintext | HIGH | 5.12% | Jul 13, 2017 |
| CVE-2011-4862 | krb5: telnet client and server encrypt_keyid heap-based buffer overflow | HIGH | 94.98% | Dec 25, 2011 |
| CVE-2007-5939 | The gss_userok function in appl/ftp/ftpd/gss_userok.c in Heimdal 0.7.2 does not allocate memory for the ticketfile pointer before calling free, which allows re… | HIGH | 3.80% | Dec 6, 2007 |
| CVE-2006-3084 | The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes… | HIGH | 0.50% | Aug 9, 2006 |
| CVE-2006-3083 | security flaw | HIGH | 0.53% | Aug 9, 2006 |
| CVE-2004-0434 | k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is… | CRITICAL | 7.16% | May 12, 2004 |
Showing 1 to 16 of 16 CVEs