CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Libssh: libssh: authentication bypass via missing gssapi principal check
Libssh: libssh: use-after-free via data callbacks on closed channels
Libssh: libssh: denial of service via automatic certificate authentication loop
Libssh: libssh: denial of service via sftp responses with unknown request ids
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
Libssh: libssh: information disclosure via proxycommand %r username expansion
Libssh: libssh: denial of service via oversized sftp read length
Libssh: libssh: denial of service via unchecked proxycommand fork() failure
Libssh: libssh: denial of service via zero advertised channel packet size
Libssh: libssh: information disclosure via short gssapi curve25519 public key
Libssh: libssh: stack buffer overflow in sftp server longname construction
Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
Libssh: libssh: denial of service via improper configuration file handling
Libssh: libssh: denial of service via inefficient regular expression processing
Libssh: libssh: denial of service due to malformed sftp message
Libssh: improper sanitation of paths received from scp servers
Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
Libssh: integer overflow in libssh sftp server packet length validation leading to denial of service
Libssh: null pointer dereference in libssh kex session id calculation
Libssh: invalid return code for chacha20 poly1305 with openssl backend
Libssh: double free vulnerability in libssh key export functions
Libssh: incorrect return code handling in ssh_kdf() in libssh
Libssh: out-of-bounds read in sftp_handle()
Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname
Showing 1 to 25 CVEs · page 1 (more available)