CVEs (134)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Openbsd6Cloud Backup Cn1610 FirmwareData Ontap Edge+3 moreDec 18, 2025 Aug 28, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that t...Show more |
7Canonical DebianNetapp+4 more22Aff Baseboard Management Controller Cloud BackupClustered Data Ontap+19 moreDec 17, 2025 Aug 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c,...Show more |
4Canonical DebianNetapp+1 more12Cloud Backup Clustered Data OntapData Ontap+9 moreApr 29, 2026 Jan 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packe...Show more |
5Debian NetappOpenbsd+2 more21Active Iq Unified Manager Cloud BackupClustered Data Ontap+18 moreMay 28, 2026 Oct 26, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. |
4Debian OpenbsdOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 29, 2026 Apr 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and...Show more |
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by lever...Show more |
The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges...Show more |
authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege...Show more |
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c. |
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket. |
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party report...Show more |
2Fedoraproject Openbsd2Fedora OpensshMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) vi...Show more |
3Canonical DebianOpenbsd5Debian Linux OpensshUbuntu Core+2 moreMay 6, 2026 May 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain priv...Show more |
2Openbsd Oracle2Openssh Vm ServerMay 29, 2026 Mar 22, 2016 N/A· v4 6.4 MEDIUM· v3 5.5 MEDIUM· v2 Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_a...Show more |
The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic. |
5Apple HpOpenbsd+2 more6Linux Mac Os XOpenssh+3 moreMay 29, 2026 Jan 14, 2016 N/A· v4 8.1 HIGH· v3 4.6 MEDIUM· v2 The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection fi...Show more |
5Apple HpOpenbsd+2 more6Linux Mac Os XOpenssh+3 moreMay 29, 2026 Jan 14, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buff...Show more |
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, a...Show more |
Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to...Show more |
The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging...Show more |