Kerberos

Vendor:

First CVE: Feb 21, 1996 · Active for 30 years

33
Total CVEs
More Total CVEs than 96% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Kerberos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 1996
30 years ago
Most Recent CVE
Dec 26, 2018
2,769 days ago

CVE Severity & Scoring

Kerberos33 CVEs
All CVEs352,713 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network5 (15.2%)
Unknown28 (84.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (9.1%)
High2 (6.1%)
Unknown28 (84.8%)
User Interaction
None5 (15.2%)
Unknown28 (84.8%)
Required0 (0.0%)
Privileges Required
Low3 (9.1%)
High0 (0.0%)
None2 (6.1%)
Unknown28 (84.8%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th
Aug 14, 200110.060NOYES
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
May 16, 200010.043NOYES
Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow re
Jan 13, 201010.032NONO
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
Aug 18, 200410.029NONO
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
May 16, 200010.026NONO
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
May 16, 200010.026NONO
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon c
Feb 22, 20107.825NONO
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the
Jan 16, 20187.524NONO
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap
Jan 16, 20186.521NONO
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer d
Feb 10, 20115.021NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Kerberos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v17.52.0%00
5-1.826.44.5%00
5-1.6.365.84.6%00
5-1.5.413.72.9%00
5-1.13.716.52.4%00
5_1.1313.51.7%00
5-1.10.724.54.6%00
5-1.10.624.54.6%00
5-1.10.524.54.6%00
4.0106.33.6%01
435.73.0%00
1.2.2.beta136.75.4%00
1.0.8110.011.7%00
1.047.513.6%01