Lucene search

K

Ssh2 Security Vulnerabilities

cve
cve

CVE-1999-0398

In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.

7AI Score

0.0004EPSS

2000-02-04 05:00 AM
27
cve
cve

CVE-1999-1029

SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.

7.1AI Score

0.009EPSS

2001-09-12 04:00 AM
26
cve
cve

CVE-1999-1231

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

7.2AI Score

0.002EPSS

2001-09-12 04:00 AM
18
cve
cve

CVE-2000-0217

The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.

6.6AI Score

0.006EPSS

2000-04-10 04:00 AM
34
cve
cve

CVE-2001-0364

SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.

7AI Score

0.011EPSS

2002-03-09 05:00 AM
24
cve
cve

CVE-2002-1644

SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.

6.7AI Score

0.001EPSS

2005-03-28 05:00 AM
25
cve
cve

CVE-2002-1645

Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.

8.2AI Score

0.018EPSS

2005-03-28 05:00 AM
47
cve
cve

CVE-2002-1715

SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.

6.7AI Score

0.0004EPSS

2005-06-21 04:00 AM
32
cve
cve

CVE-2020-26301

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted inp...

10CVSS

9.8AI Score

0.04EPSS

2021-09-20 08:15 PM
36
cve
cve

CVE-2023-48795

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connecti...

5.9CVSS

6.7AI Score

0.963EPSS

2023-12-18 04:15 PM
480