← Vulnerability feed

Vulnerability record · CVE-2021-44758 · published 26 December 2022

CVE-2021-44758: Heimdal project heimdal null pointer dereference vulnerability

Heimdal Project · Heimdal

Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.

7.5 CVSS 3.1 High EPSS 1.2% · top 32.4% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-44758 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4862telnetd encryption key buffer overflow allows remote code executionA buffer overflow in libtelnet/encrypt.c in telnetd affects FreeBSD 7.3 through 9.0, MIT krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU …EPSS 95%analysed9.8CVE-2022-44640Heimdal project heimdal double free vulnerabilityHeimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Cen…EPSS 1.8%9.8CVE-2004-0434Heimdal project heimdal vulnerabilityk5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing …EPSS 7.2%8.8CVE-2022-42898Mit kerberos 5 integer overflow vulnerabilityPAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC,…EPSS 6.2%8.1CVE-2017-11103Heimdal project heimdal insufficient verification of data authenticity vulnerabilityHeimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way tha…EPSS 5.1%7.5CVE-2022-3116Heimdal project heimdal null pointer dereference vulnerabilityThe Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that de…EPSS 0.89%7.5CVE-2022-45142Heimdal project heimdal vulnerabilityThe fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result…EPSS 0.49%7.5CVE-2022-41916Heimdal project heimdal vulnerabilityHeimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2021-44758), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.