Libssh2
libssh2
21 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free op...Show more |
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on...Show more |
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose...Show more |
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH pack...Show more |
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exha...Show more |
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory. |
5Debian FedoraprojectLibssh2+2 more10Active Iq Unified Manager Bootstrap OsDebian Linux+7 moreJun 17, 2026 Oct 21, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read...Show more |
5Debian F5Fedoraproject+2 more7Cloud Backup Debian LinuxE Series Santricity Os Controller+4 moreJun 17, 2026 Jul 16, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attack...Show more |
4Debian Libssh2Netapp+1 more4Debian Linux LeapLibssh2+1 moreJun 17, 2026 Mar 25, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able t...Show more |
4Debian Libssh2Netapp+1 more4Debian Linux LeapLibssh2+1 moreJun 17, 2026 Mar 25, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read da...Show more |
7Debian FedoraprojectLibssh2+4 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreJun 17, 2026 Mar 25, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SS...Show more |
7Debian FedoraprojectLibssh2+4 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreJun 17, 2026 Mar 25, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to e...Show more |
5Debian Libssh2Netapp+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Mar 25, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max charac...Show more |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service...Show more |
8Apple DebianFedoraproject+5 more14Debian Linux Enterprise LinuxEnterprise Linux Desktop+11 moreJun 17, 2026 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execut...Show more |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be ab...Show more |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Ser...Show more |
4Debian FedoraprojectLibssh2+1 more4Debian Linux FedoraLibssh2+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecif...Show more |