VendorsMITkerberos4
Vulnerabilities

MIT Kerberos 4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2003-0138
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.
Published 2003-03-21 · Modified
7.5EPSS 0.043
CVE-2003-0139
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."
Published 2003-03-21 · Modified
7.5EPSS 0.043
CVE-2001-0417
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
Published 2001-05-24 · Modified
2.1EPSS 0.004