Kerberos 5
Vendor:
First CVE: Feb 21, 1996 · Active for 30 years
140
Total CVEs
More Total CVEs than 99% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kerberos 5 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 1996
30 years ago
Most Recent CVE
Apr 28, 2026
90 days ago
CVE Severity & Scoring
Kerberos 5140 CVEs
41%
48%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.7%)
Network34 (24.3%)
Unknown105 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (21.4%)
High5 (3.6%)
Unknown105 (75.0%)
User Interaction
None35 (25.0%)
Unknown105 (75.0%)
Required0 (0.0%)
Privileges Required
Low14 (10.0%)
High2 (1.4%)
None19 (13.6%)
Unknown105 (75.0%)
Top CVEs
Signals from CVEs in this product scope (140 CVEs).
140 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0554HIGH Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th | Aug 14, 2001 | 10.0 | 60 | NO | YES |
CVE-2011-0285HIGH The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows r | Apr 15, 2011 | 10.0 | 54 | NO | YES |
CVE-2001-0247HIGH Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_ | Jun 18, 2001 | 10.0 | 52 | NO | YES |
CVE-2007-0956HIGH The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a simila | Apr 6, 2007 | 10.0 | 43 | NO | NO |
CVE-2000-0389HIGH Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges. | May 16, 2000 | 10.0 | 43 | NO | YES |
CVE-2016-3119MEDIUM The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14 | Mar 26, 2016 | 5.3 | 39 | NO | NO |
CVE-2009-3295MEDIUM The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 al | Dec 29, 2009 | 5.0 | 38 | NO | NO |
CVE-2026-40356HIGH In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoE | Apr 28, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-40355HIGH In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in / | Apr 28, 2026 | 7.5 | 36 | NO | NO |
CVE-2017-15088CRITICAL plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbit | Nov 23, 2017 | 9.8 | 36 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (140 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
3.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (140 CVEs).
Media Mentions
Signals from CVEs in this product scope (140 CVEs).
Top CNAs Publishing CVEs For Kerberos 5
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.4 | 6 | 6.6 | 11.1% | 0 | 0 |
| 1.9.3 | 6 | 5.7 | 10.8% | 0 | 0 |
| 1.9.2 | 6 | 5.7 | 10.8% | 0 | 0 |
| 1.9.1 | 9 | 6.4 | 8.5% | 0 | 0 |
| 1.9 | 15 | 6.3 | 8.0% | 0 | 1 |
| 1.8.6 | 7 | 6.2 | 9.9% | 0 | 0 |
| 1.8.5 | 7 | 6.2 | 9.9% | 0 | 0 |
| 1.8.4 | 10 | 6.7 | 8.1% | 0 | 0 |
| 1.8.3 | 18 | 6.4 | 7.1% | 0 | 1 |
| 1.8.2 | 18 | 6.4 | 7.1% | 0 | 1 |
| 1.8.1 | 19 | 6.3 | 7.4% | 0 | 2 |
| 1.8 | 21 | 6.1 | 7.0% | 0 | 2 |
| 1.7.1 | 14 | 5.9 | 8.6% | 0 | 2 |
| 1.7 | 18 | 5.8 | 9.7% | 0 | 2 |
| 1.6.3 | 1 | 10.0 | 8.8% | 0 | 0 |
| 1.6.2 | 12 | 6.9 | 8.8% | 0 | 0 |
| 1.6.1 | 12 | 6.9 | 8.8% | 0 | 0 |
| 1.6 | 12 | 6.9 | 8.8% | 0 | 0 |
| 1.5.3 | 9 | 7.2 | 9.9% | 0 | 0 |
| 1.5.2 | 11 | 6.7 | 8.2% | 0 | 0 |