← Vulnerability feed

Vulnerability record · CVE-2022-3116 · published 27 March 2023

CVE-2022-3116: Heimdal project heimdal null pointer dereference vulnerability

Heimdal Project · Heimdal

The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.

7.5 CVSS 3.1 High EPSS 0.89% · top 42.2% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-3116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4862telnetd encryption key buffer overflow allows remote code executionA buffer overflow in libtelnet/encrypt.c in telnetd affects FreeBSD 7.3 through 9.0, MIT krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU …EPSS 95%analysed9.8CVE-2022-44640Heimdal project heimdal double free vulnerabilityHeimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Cen…EPSS 1.8%9.8CVE-2004-0434Heimdal project heimdal vulnerabilityk5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing …EPSS 7.2%8.8CVE-2022-42898Mit kerberos 5 integer overflow vulnerabilityPAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC,…EPSS 6.2%8.1CVE-2017-11103Heimdal project heimdal insufficient verification of data authenticity vulnerabilityHeimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way tha…EPSS 5.1%7.5CVE-2022-45142Heimdal project heimdal vulnerabilityThe fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result…EPSS 0.49%7.5CVE-2021-44758Heimdal project heimdal null pointer dereference vulnerabilityHeimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzer…EPSS 1.2%7.5CVE-2022-41916Heimdal project heimdal vulnerabilityHeimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2022-3116), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.