CVE-2009-0846

10.0
CVSS v2.0 Base Score
8.90%
LOW RiskEPSS (95th percentile)

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

Published: 4/9/2009
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

8.90%LOW Exploitation Risk
95th percentile

This vulnerability has a 8.90% probability of being exploited in the next 30 days, ranking higher than 95% of all scored CVEs.

CWE Classification

Advertisement