AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-5353

LOW · CVSS 3.5 EPSS 4.97% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-12-16 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2014-5353
Severity
LOW
CVSS
3.5
EPSS
4.97%

Original Filing — NVD Description

The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.