Vulnerabilities > Heimdal Project > Heimdal > 7.7.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-27 | CVE-2022-3116 | NULL Pointer Dereference vulnerability in Heimdal Project Heimdal The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. | 7.5 |
2022-12-26 | CVE-2021-44758 | NULL Pointer Dereference vulnerability in Heimdal Project Heimdal Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept. | 7.5 |
2022-12-25 | CVE-2022-42898 | Integer Overflow or Wraparound vulnerability in multiple products PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. | 8.8 |
2022-12-25 | CVE-2022-44640 | Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). | 9.8 |
2022-11-15 | CVE-2022-41916 | Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. | 7.5 |