Dropbear Ssh Project / Dropbear Ssh
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-47203 | dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used. | MEDIUM | 4.5 | May 7, 2025 |
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 5.9 | Dec 18, 2023 |
| CVE-2021-36369 | An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it i… | HIGH | 7.5 | Oct 12, 2022 |
| CVE-2020-36254 | scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685. | HIGH | 8.1 | Feb 25, 2021 |
| CVE-2019-12953 | Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599. | MEDIUM | 5.3 | Dec 30, 2020 |
| CVE-2017-2659 | It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI a… | HIGH | 7.5 | Mar 20, 2019 |
| CVE-2018-15599 | The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects… | MEDIUM | 5.3 | Aug 21, 2018 |
| CVE-2017-9079 | Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occ… | MEDIUM | 4.7 | May 19, 2017 |
| CVE-2017-9078 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the… | HIGH | 8.8 | May 19, 2017 |
| CVE-2016-7409 | The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related… | MEDIUM | 5.5 | Mar 3, 2017 |
| CVE-2016-7408 | The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument. | HIGH | 8.8 | Mar 3, 2017 |
| CVE-2016-7407 | The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file. | CRITICAL | 9.8 | Mar 3, 2017 |
| CVE-2016-7406 | Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username o… | CRITICAL | 9.8 | Mar 3, 2017 |
| CVE-2016-3116 | CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 for… | MEDIUM | 6.4 | Mar 22, 2016 |
| CVE-2013-4434 | Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists,… | MEDIUM | 5.0 | Oct 25, 2013 |
| CVE-2013-4421 | The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a c… | MEDIUM | 5.0 | Oct 25, 2013 |
| CVE-2012-0920 | Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote aut… | HIGH | 7.1 | Jun 5, 2012 |
| CVE-2007-1099 | dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to condu… | HIGH | 7.5 | Feb 26, 2007 |
| CVE-2006-1206 | Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to caus… | MEDIUM | 5.0 | Mar 14, 2006 |
| CVE-2005-4178 | Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be… | MEDIUM | 6.5 | Dec 12, 2005 |
| CVE-2004-2486 | The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access. | HIGH | 7.5 | Oct 25, 2005 |
Showing 1 to 20 of 20 CVEs