Multiple Vulnerabilities in MIT Kerberos 5 Identified and Published
First seen 18 Feb 2026, 13:23 UTC
•
•34
Export
Article Content
Browse articles
Two vulnerabilities in MIT Kerberos 5 (krb5) before version 1.21.3 have been identified. CVE-2024-37370 allows an attacker to modify the Extra Count field of a GSS krb5 wrap token, while CVE-2024-37371 enables invalid memory reads during GSS message token handling. Both vulnerabilities were published on June 28, 2024.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2024-06-28
CVE-2024-37370 published
2024-06-28
CVE-2024-37371 published
2026-02-18
Information published about CVE-2024-37370 and CVE-2024-37371
More articles in this cluster
Continue Reading
Google Addresses Unreported Chrome Zero-Day Vulnerability
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
Apple Fixes Zero-Day Vulnerability in Software Update
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
Cisco Addresses AsyncOS Zero-Day Exploited by Threat Actors