Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mit

First CVE: Feb 21, 1996Active for: 30 yearsTotal CVEs: 160
43.7
VTI Score
High

MIT's vulnerability footprint centers on Kerberos and related authentication infrastructure, foundational components embedded across enterprise networks, operating systems, and distributed systems despite a narrow product scope. Vulnerabilities affecting the vendor lean toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the authentication layer's centrality to system compromise chains. The exposure recurs through weakness classes including improper input validation, NULL-pointer dereferences, buffer-boundary violations, and double-free conditions—memory-safety and parsing issues endemic to long-running, protocol-heavy code that processes untrusted network input. Defenders should treat Kerberos disclosures as high-priority across heterogeneous platforms, since a single flaw can cascade through Windows domains, Unix environments, and embedded services simultaneously. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
160
Total CVEs
More Total CVEs than 100% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 1996
30 years ago
Most Recent CVE
Apr 28, 2026
87 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (160 CVEs).

160 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-4862HIGH
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU
Dec 25, 201110.092NOYES
CVE-2001-0554HIGH
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th
Aug 14, 200110.060NOYES
CVE-2011-0285HIGH
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows r
Apr 15, 201110.052NOYES
CVE-2001-0247HIGH
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_
Jun 18, 200110.052NOYES
CVE-2007-0956HIGH
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a simila
Apr 6, 200710.043NONO
CVE-2000-0389HIGH
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
May 16, 200010.043NOYES
CVE-2020-7750CRITICAL
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary el
Oct 21, 20209.642NOYES
CVE-2016-3119MEDIUM
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14
Mar 26, 20165.339NONO
CVE-2009-3295MEDIUM
The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 al
Dec 29, 20095.038NONO
CVE-2026-40356HIGH
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoE
Apr 28, 20267.536NONO
View all 160 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products160 CVEs
41%
48%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.3%)
Network42 (26.3%)
Unknown116 (72.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (23.1%)
High7 (4.4%)
Unknown116 (72.5%)
User Interaction
None42 (26.3%)
Unknown116 (72.5%)
Required2 (1.3%)
Privileges Required
Low17 (10.6%)
High2 (1.3%)
None25 (15.6%)
Unknown116 (72.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (160 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
5.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mit's Products

View all 4 CNAs →

Top CWEs