Ssh / Ssh
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 5.9 | Dec 18, 2023 |
| CVE-2011-0766 | The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictab… | HIGH | 7.8 | May 31, 2011 |
| CVE-2002-1715 | SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable d… | HIGH | 7.2 | Jun 21, 2005 |
| CVE-2001-1476 | SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords… | HIGH | 7.5 | Apr 21, 2005 |
| CVE-2001-1475 | SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated. | HIGH | 7.5 | Apr 21, 2005 |
| CVE-2001-1474 | SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the localhost by… | MEDIUM | 5.0 | Apr 21, 2005 |
| CVE-2001-1473 | The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session I… | HIGH | 7.5 | Apr 21, 2005 |
| CVE-2001-1470 | The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block wi… | MEDIUM | 5.0 | Apr 21, 2005 |
| CVE-2001-1469 | The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CR… | MEDIUM | 5.0 | Apr 21, 2005 |
| CVE-2000-0575 | SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, whic… | HIGH | 7.2 | Mar 9, 2002 |
| CVE-2001-0361 | Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allo… | MEDIUM | 4.0 | Sep 18, 2001 |
| CVE-2001-0572 | security flaw | HIGH | 7.5 | Jul 27, 2001 |
| CVE-2001-0471 | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts w… | HIGH | 7.5 | May 24, 2001 |
| CVE-2001-0259 | ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker c… | LOW | 3.6 | May 7, 2001 |
| CVE-2001-0144 | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow. | HIGH | 10.0 | May 7, 2001 |
| CVE-2000-0992 | Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. | MEDIUM | 5.0 | Jan 22, 2001 |
| CVE-1999-0787 | The SSH authentication agent follows symlinks via a UNIX domain socket. | LOW | 2.1 | Oct 13, 2000 |
| CVE-1999-0248 | A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials. | HIGH | 10.0 | Oct 13, 2000 |
| CVE-2000-0217 | The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program. | MEDIUM | 5.1 | Apr 10, 2000 |
| CVE-2000-0143 | The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password data… | MEDIUM | 4.6 | Feb 16, 2000 |
| CVE-1999-0398 | In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. | MEDIUM | 4.6 | Feb 4, 2000 |
| CVE-1999-0013 | Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user. | HIGH | 8.4 | Sep 29, 1999 |
Showing 1 to 22 of 22 CVEs