Kerberos
Vendor:
First CVE: Feb 21, 1996 · Active for 30 years
33
Total CVEs
More Total CVEs than 96% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kerberos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 1996
30 years ago
Most Recent CVE
Dec 26, 2018
2,769 days ago
CVE Severity & Scoring
Kerberos33 CVEs
9%
55%
36%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network5 (15.2%)
Unknown28 (84.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (9.1%)
High2 (6.1%)
Unknown28 (84.8%)
User Interaction
None5 (15.2%)
Unknown28 (84.8%)
Required0 (0.0%)
Privileges Required
Low3 (9.1%)
High0 (0.0%)
None2 (6.1%)
Unknown28 (84.8%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0554HIGH Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th | Aug 14, 2001 | 10.0 | 60 | NO | YES |
CVE-2000-0389HIGH Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges. | May 16, 2000 | 10.0 | 43 | NO | YES |
CVE-2009-4212HIGH Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow re | Jan 13, 2010 | 10.0 | 32 | NO | NO |
CVE-2004-0523HIGH Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root. | Aug 18, 2004 | 10.0 | 29 | NO | NO |
CVE-2000-0390HIGH Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges. | May 16, 2000 | 10.0 | 26 | NO | NO |
CVE-2000-0391HIGH Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges. | May 16, 2000 | 10.0 | 26 | NO | NO |
CVE-2010-0283HIGH The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon c | Feb 22, 2010 | 7.8 | 25 | NO | NO |
CVE-2018-5709HIGH An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the | Jan 16, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-5710MEDIUM An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap | Jan 16, 2018 | 6.5 | 21 | NO | NO |
CVE-2011-0282MEDIUM The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer d | Feb 10, 2011 | 5.0 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Kerberos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| v | 1 | 7.5 | 2.0% | 0 | 0 |
| 5-1.8 | 2 | 6.4 | 4.5% | 0 | 0 |
| 5-1.6.3 | 6 | 5.8 | 4.6% | 0 | 0 |
| 5-1.5.4 | 1 | 3.7 | 2.9% | 0 | 0 |
| 5-1.13.7 | 1 | 6.5 | 2.4% | 0 | 0 |
| 5_1.13 | 1 | 3.5 | 1.7% | 0 | 0 |
| 5-1.10.7 | 2 | 4.5 | 4.6% | 0 | 0 |
| 5-1.10.6 | 2 | 4.5 | 4.6% | 0 | 0 |
| 5-1.10.5 | 2 | 4.5 | 4.6% | 0 | 0 |
| 4.0 | 10 | 6.3 | 3.6% | 0 | 1 |
| 4 | 3 | 5.7 | 3.0% | 0 | 0 |
| 1.2.2.beta1 | 3 | 6.7 | 5.4% | 0 | 0 |
| 1.0.8 | 1 | 10.0 | 11.7% | 0 | 0 |
| 1.0 | 4 | 7.5 | 13.6% | 0 | 1 |