Kerberos 5

Vendor:

First CVE: Feb 21, 1996 · Active for 30 years

140
Total CVEs
More Total CVEs than 99% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Kerberos 5 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 1996
30 years ago
Most Recent CVE
Apr 28, 2026
90 days ago

CVE Severity & Scoring

Kerberos 5140 CVEs
All CVEs352,727 CVEs
LowMediumHighCritical
Attack Vector
Local1 (0.7%)
Network34 (24.3%)
Unknown105 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (21.4%)
High5 (3.6%)
Unknown105 (75.0%)
User Interaction
None35 (25.0%)
Unknown105 (75.0%)
Required0 (0.0%)
Privileges Required
Low14 (10.0%)
High2 (1.4%)
None19 (13.6%)
Unknown105 (75.0%)

Top CVEs

Signals from CVEs in this product scope (140 CVEs).

140 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th
Aug 14, 200110.060NOYES
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows r
Apr 15, 201110.054NOYES
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_
Jun 18, 200110.052NOYES
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a simila
Apr 6, 200710.043NONO
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
May 16, 200010.043NOYES
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14
Mar 26, 20165.339NONO
The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 al
Dec 29, 20095.038NONO
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoE
Apr 28, 20267.536NONO
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /
Apr 28, 20267.536NONO
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbit
Nov 23, 20179.836NONO

Exploit Exposure

Signals from CVEs in this product scope (140 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
3.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (140 CVEs).

Media Mentions

Signals from CVEs in this product scope (140 CVEs).

Top CNAs Publishing CVEs For Kerberos 5

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.466.611.1%00
1.9.365.710.8%00
1.9.265.710.8%00
1.9.196.48.5%00
1.9156.38.0%01
1.8.676.29.9%00
1.8.576.29.9%00
1.8.4106.78.1%00
1.8.3186.47.1%01
1.8.2186.47.1%01
1.8.1196.37.4%02
1.8216.17.0%02
1.7.1145.98.6%02
1.7185.89.7%02
1.6.3110.08.8%00
1.6.2126.98.8%00
1.6.1126.98.8%00
1.6126.98.8%00
1.5.397.29.9%00
1.5.2116.78.2%00