Known Vulnerabilities for Krb5 1.5 by Na
Listed below are 9 of the newest known vulnerabilities associated with "Krb5 1.5" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40356 json | In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application ... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-40355 json | In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_contex... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-33995 json | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in kerb... | Not Provided | 2026-03-30 | 2026-03-30 |
| CVE-2026-31932 json | Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-31392 json | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Custom... | Not Provided | 2026-04-03 | 2026-04-27 |
| CVE-2025-38562 json | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_en... | Not Provided | 2025-08-19 | 2026-04-18 |
| CVE-2024-37371 json | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by s... | Not Provided | 2024-06-28 | 2026-05-12 |
| CVE-2024-37370 json | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5... | Not Provided | 2024-06-28 | 2026-05-12 |
| CVE-2019-12098 json | In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the... | Not Provided | 2019-05-15 | 2026-04-15 |