AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-0628

MEDIUM · CVSS 5 EPSS 3.33%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-03-25 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2010-0628
Severity
MEDIUM
CVSS
5
EPSS
3.33%

Original NVD Description

The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid packet that triggers incorrect preparation of an error token.