CVEs (134)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
13Almalinux AmazonApple+10 more53500f Firmware 8300 Firmware8700 Firmware+50 moreJun 17, 2026 Jul 1, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more |
3Fedoraproject OpenbsdRedhat3Enterprise Linux FedoraOpensshJun 17, 2026 Dec 24, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single...Show more |
2Debian Openbsd2Debian Linux OpensshJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git...Show more |
2Debian Openbsd2Debian Linux OpensshJul 14, 2026 Dec 18, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only appli...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
2Fedoraproject Openbsd2Fedora OpensshJun 17, 2026 Jul 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not...Show more |
2Netapp Openbsd4Brocade Fabric Operating System Hci Bootstrap OsOpenssh+1 moreJul 14, 2026 Mar 17, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. |
3Fedoraproject NetappOpenbsd6500f Firmware A250 FirmwareC250 Firmware+3 moreJun 17, 2026 Feb 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the defaul...Show more |
2Debian Openbsd2Debian Linux OpensshJun 17, 2026 Mar 13, 2022 N/A· v4 3.7 LOW· v3 2.6 LOW· v2 An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None aut...Show more |
5Fedoraproject NetappOpenbsd+2 more12Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+9 moreJul 14, 2026 Sep 26, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCom...Show more |
2Netapp Openbsd5Clustered Data Ontap Hci Management NodeOntap Select Deploy Administration Utility+2 moreMay 29, 2026 Sep 15, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challeng...Show more |
4Fedoraproject NetappOpenbsd+1 more9Cloud Backup Communications Offline Mediation ControllerFedora+6 moreJun 17, 2026 Mar 5, 2021 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-...Show more |
3Broadcom NetappOpenbsd9A700s Firmware Active Iq Unified ManagerFabric Operating System+6 moreJun 17, 2026 Jul 24, 2020 N/A· v4 7.4 HIGH· v3 6.8 MEDIUM· v2 scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omi...Show more |
2Netapp Openbsd9Active Iq Unified Manager Aff A700s FirmwareHci Compute Node+6 moreJun 17, 2026 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where n...Show more |
The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the cli...Show more |
3Netapp OpenbsdSiemens5Cloud Backup OpensshScalance X204rna Ecc Firmware+2 moreJun 17, 2026 Oct 9, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corru...Show more |
10Apache CanonicalDebian+7 more19Debian Linux Enterprise LinuxEnterprise Linux Eus+16 moreJun 17, 2026 Jan 31, 2019 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validati...Show more |
4Netapp OpenbsdSiemens+1 more7Element Software Ontap Select DeployOpenssh+4 moreJun 17, 2026 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide...Show more |
9Canonical DebianFedoraproject+6 more20Debian Linux Element SoftwareEnterprise Linux+17 moreJun 17, 2026 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g.,...Show more |
9Canonical DebianFujitsu+6 more22Cloud Backup Debian LinuxElement Software+19 moreDec 17, 2025 Jan 10, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the...Show more |