Lucene search

K

Freesshd Security Vulnerabilities

cve
cve

CVE-2006-2407

Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.

7.7AI Score

0.688EPSS

2006-05-16 10:02 AM
48
cve
cve

CVE-2008-0852

freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.

6.7AI Score

0.053EPSS

2008-02-21 12:44 AM
21
cve
cve

CVE-2008-2573

Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) command.

7.7AI Score

0.088EPSS

2008-06-06 06:32 PM
25
cve
cve

CVE-2008-4762

Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argument to the (1) rename and (2) realpath parameters.

7.7AI Score

0.076EPSS

2008-10-28 02:00 AM
31
cve
cve

CVE-2008-6899

Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a long (1) open, (2) unlink, (3) mkdir, (4) rmdir, or (5) stat SFTP command.

7.8AI Score

0.022EPSS

2009-08-05 10:30 PM
23
cve
cve

CVE-2009-3340

Unspecified vulnerability in FreeSSHD 1.2.4 allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack aut...

6.7AI Score

0.008EPSS

2009-09-24 04:30 PM
31
cve
cve

CVE-2012-6066

freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.

6.9AI Score

0.505EPSS

2012-12-04 11:55 PM
50
cve
cve

CVE-2017-1000475

FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.

7.8CVSS

8AI Score

0.001EPSS

2018-01-24 02:29 PM
40
cve
cve

CVE-2018-9853

Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to login to an unprivileged account on the server.

9.8CVSS

9.2AI Score

0.003EPSS

2018-07-10 02:29 PM
31
cve
cve

CVE-2022-27052

FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

7.8CVSS

8AI Score

0.0004EPSS

2022-03-31 11:15 PM
75
cve
cve

CVE-2024-0723

A vulnerability was found in freeSSHd 1.0.9 on Windows. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated iden...

7.5CVSS

7.5AI Score

0.001EPSS

2024-01-19 05:15 PM
9