← Back

Openssh

openssh

Vendor: Openbsd • 137 CVEs

CVEs (137)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbsd
1Openssh
Apr 16, 2026
Aug 23, 2005
N/A· v4
N/A· v3
1.2 LOW· v2
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an S...Show more
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a list of additional targets that are more likely to have the same password or key.Show less
1Openbsd
1Openssh
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
6.8 MEDIUM· v2
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect passw...Show more
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2003-0190. NOTE: it could be argued that in most environments, this does not cross privilege boundaries without requiring leverage of a separate vulnerability.Show less
1Openbsd
1Openssh
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTim...Show more
sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).Show less
1Openbsd
1Openssh
Apr 16, 2026
Aug 31, 2004
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
1Openbsd
1Openssh
Apr 16, 2026
Aug 18, 2004
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.
1Openbsd
1Openssh
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.6 HIGH· v2
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier...Show more
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.Show less
1Openbsd
1Openssh
Apr 16, 2026
Nov 17, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.
1Openbsd
1Openssh
Apr 16, 2026
Nov 17, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privil...Show more
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.Show less
1Openbsd
1Openssh
Apr 16, 2026
Oct 6, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate fun...Show more
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.Show less
1Openbsd
1Openssh
Apr 16, 2026
Oct 6, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
1Openbsd
1Openssh
Apr 16, 2026
Sep 22, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a d...Show more
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.Show less
1Openbsd
1Openssh
Apr 16, 2026
Jul 2, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a ho...Show more
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.Show less
3Openbsd
OpenpkgSiemens
4Openpkg
OpensshScalance X204rna Ecc Firmware+1 more
Apr 16, 2026
May 12, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
1Openbsd
2Openbsd
Openssh
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
1Openbsd
1Openssh
Apr 16, 2026
Jul 3, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with in...Show more
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).Show less
1Openbsd
1Openssh
Apr 16, 2026
Jul 3, 2002
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH au...Show more
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.Show less
1Openbsd
1Openssh
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges.
9Conectiva
EngardelinuxImmunix+6 more
11Immunix
LinuxLinux+8 more
Apr 16, 2026
Mar 15, 2002
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
1Openbsd
1Openssh
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has th...Show more
SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user's authorized_keys file.Show less
1Openbsd
1Openssh
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.