← Back

Ssh2

ssh2

Vendor: Ssh • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ssh
2Ssh
Ssh2
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell acc...Show more
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.Show less
1Ssh
1Ssh2
Apr 16, 2026
Nov 25, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.
1Ssh
1Ssh2
Apr 16, 2026
Nov 25, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which al...Show more
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.Show less
1Ssh
1Ssh2
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.
2Openbsd
Ssh
3Openssh
SshSsh2
Apr 16, 2026
Feb 24, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
1Ssh
1Ssh2
Apr 16, 2026
Jun 9, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determ...Show more
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.Show less
1Ssh
1Ssh2
Apr 16, 2026
May 13, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit lo...Show more
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.Show less
1Ssh
2Ssh
Ssh2
Apr 16, 2026
Jan 1, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
1Ssh
1Ssh2
Apr 16, 2026
Dec 29, 1998
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.