Kth maintains a modestly represented but notably prominent portfolio centered on authentication infrastructure, primarily the Kerberos implementation (Heimdal and KTH Kerberos variants) alongside audio processing components. The vulnerability exposure recurs through memory-safety and buffer-boundary issues characteristic of C-based protocol and codec implementations, and exhibits an elevated tendency toward public exploit availability. Defenders should monitor this vendor's Kerberos releases closely given the authentication tier's role in network access and identity; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kth over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6303MEDIUM Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denia | Oct 28, 2013 | 6.8 | 38 | NO | YES |
CVE-2002-1235HIGH The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eB | Nov 4, 2002 | 10.0 | 33 | NO | NO |
CVE-2002-1226HIGH Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access | Oct 28, 2002 | 10.0 | 30 | NO | NO |
CVE-2001-0034HIGH KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges | Feb 16, 2001 | 7.2 | 27 | NO | YES |
CVE-2002-1225HIGH Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access. | Oct 28, 2002 | 10.0 | 26 | NO | NO |
CVE-2001-0035HIGH Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authenti | Feb 16, 2001 | 7.2 | 24 | NO | NO |
CVE-2006-0677HIGH telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a | Feb 14, 2006 | 7.8 | 21 | NO | NO |
CVE-2002-0600HIGH Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request. | Jun 18, 2002 | 7.5 | 20 | NO | NO |
CVE-2001-1444HIGH The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows | Aug 27, 2001 | 7.5 | 19 | NO | NO |
CVE-2002-0754HIGH Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to rega | Aug 12, 2002 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kth.
Media articles that mention a CVE ID that affects a product developed by Kth — matched by CVE ID, not by vendor name.