Home/Product/openbsd openssh
Product

openbsd openssh

165 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-35414
< 10.3
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunct
4.2MEDIUM
CVE-2026-35388
< 10.3
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
2.5LOW
CVE-2026-35387
< 10.3
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAc
3.1LOW
CVE-2026-35386
< 10.3
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a
3.6LOW
CVE-2026-35385
< 10.3
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectation
7.5HIGH
CVE-2025-32755
all versions
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, caus
9.1CRITICAL
CVE-2025-32754
< 6.11.2
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, c
9.1CRITICAL
CVE-2025-32728
>= 7.4 and < 10.0
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11
4.3MEDIUM
CVE-2025-26466
all versions
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buff
5.9MEDIUM
CVE-2025-26465
>= 6.9 and <= 9.8
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed
6.8MEDIUM
CVE-2024-6387
< 4.4
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to
8.1HIGH
CVE-2023-51767
all versions
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the i
7.0HIGH
CVE-2023-51385
< 9.6
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name
6.5MEDIUM
CVE-2023-51384
>= 8.9 and < 9.6
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are
5.5MEDIUM
CVE-2023-48795
< 9.6
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9MEDIUM
CVE-2023-41939
<= 1.4
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowi
8.8HIGH
CVE-2023-38408
< 9.3
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code exe
9.8CRITICAL
CVE-2023-28531
>= 8.9 and < 9.3
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest
9.8CRITICAL
CVE-2023-25136
all versions
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH
6.5MEDIUM
CVE-2021-43565
< 0.0.0-20211202192323-5770296d904e
The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server
7.5HIGH
CVE-2022-30959
<= 2.6.1
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an
6.5MEDIUM
CVE-2022-30958
<= 2.6.1
A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attack
8.8HIGH
CVE-2022-30957
<= 2.6.1
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate cred
4.3MEDIUM
CVE-2022-27191
< 0.0.0-20220314234659-1baeb1ce4c0b
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certai
7.5HIGH
CVE-2021-36368
< 8.9
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -o
3.7LOW
CVE-2021-41617
>= 6.2 and < 8.8
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because
7.0HIGH
CVE-2016-20012
<= 8.7
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known t
5.3MEDIUM
CVE-2021-27893
< 6.4.19
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on
7.0HIGH
CVE-2021-27892
< 6.4.19
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected.
7.8HIGH
CVE-2021-27891
< 6.4.19
SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.
8.8HIGH
CVE-2021-28041
>= 8.2 and < 8.5
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent
7.1HIGH
CVE-2020-29652
<= 0.0.0-20201203163018-be400aefbc4c
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote
7.5HIGH
CVE-2020-15778
< 8.3
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in th
7.4HIGH
CVE-2020-14145
>= 5.7 and < 8.4
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiati
5.9MEDIUM
CVE-2020-12062
all versions
The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows
7.5HIGH
CVE-2019-16905
>= 7.7 and <= 7.9
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow
7.8HIGH
CVE-2019-6111
<= 7.9
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/
5.9MEDIUM
CVE-2019-6110
<= 7.9
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle
6.8MEDIUM
CVE-2019-6109
<= 7.9
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-T
6.8MEDIUM
CVE-2018-20685
<= 7.9
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or
5.3MEDIUM
CVE-2018-15919
>= 5.9 and <= 7.8
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users
5.3MEDIUM
CVE-2018-15473
<= 7.7
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user un
5.3MEDIUM
CVE-2016-10708
< 7.4
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an
7.5HIGH
CVE-2017-1000245
<= 2.4
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases f
9.8CRITICAL
CVE-2017-15906
< 7.6
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, whic
5.3MEDIUM
CVE-2016-1908
< 7.2
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 serv
9.8CRITICAL
CVE-2016-6210
<= 7.2
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password w
5.9MEDIUM
CVE-2016-10012
<= 7.3
The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bo
7.8HIGH
CVE-2016-10011
<= 7.3
authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow l
6.2MEDIUM
CVE-2016-10010
<= 7.3
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allo
7.0HIGH
CVE-2016-10009
<= 7.3
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary
7.3HIGH
CVE-2016-8858
all versions
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (m
7.5HIGH
CVE-2016-6515
<= 7.2
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authenticat
7.5HIGH
CVE-2015-8325
<= 7.2
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configure
7.8HIGH
CVE-2016-3115
<= 7.2
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass in
6.4MEDIUM
CVE-2016-1907
all versions
The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-o
5.3MEDIUM
CVE-2016-0778
all versions
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2,
8.1HIGH
CVE-2016-0777
all versions
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obt
6.5MEDIUM
CVE-2015-6565
all versions
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service
CVE-2015-6564
<= 6.9
Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD plat
7.0HIGH
CVE-2015-6563
<= 6.9
The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_I
6.4MEDIUM
CVE-2015-5600
<= 6.9
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keybo
8.1HIGH
CVE-2015-5352
<= 6.8
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of
CVE-2014-9278
all versions
The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote aut
CVE-2014-2653
<= 6.6
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skippin
6.5MEDIUM
CVE-2014-2532
<= 6.5
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to
4.2MEDIUM
CVE-2011-4327
<= 5.8
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descr
5.5MEDIUM
CVE-2014-1692
<= 6.4
The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does no
7.3HIGH
CVE-2013-4548
all versions
The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not prope
CVE-2010-5107
<= 6.1
The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing
7.5HIGH
CVE-2012-5975
all versions
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and
CVE-2011-5000
<= 5.8
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allo
CVE-2012-0814
<= 5.6
The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys
6.5MEDIUM
CVE-2011-0766
<= 2.0.4
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library
CVE-2010-4755
<= 5.8
The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in Free
CVE-2011-0539
all versions
The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-lin
7.5HIGH
CVE-2010-4478
<= 5.6
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which al
9.8CRITICAL
CVE-2009-2904
all versions
A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise
CVE-2008-5161
all versions
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.
3.7LOW
CVE-2008-4109
<= 4.3p2
A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such a
CVE-2008-3844
all versions
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key,
CVE-2008-3259
<= 5.0
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows lo
CVE-2008-3234
all versions
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to ar
CVE-2008-1657
all versions
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modify
CVE-2008-1483
all versions
OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to
CVE-2007-5616
>= 5.0 and < 5.2.4
ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain
CVE-2007-3102
all versions
Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other s
CVE-2007-4752
<= 4.6
ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instea
CVE-2007-4654
all versions
Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) ser
CVE-2007-2768
all versions
OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain
CVE-2007-2243
all versions
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of us
CVE-2007-2063
<= 5.3.0
SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows loc
CVE-2006-5794
<= 4.4
Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentic
CVE-2006-5484
<= 5.1.0
SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with ex
CVE-2006-5229
all versions
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows r
CVE-2006-4925
all versions
packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence wi
CVE-2006-5052
all versions
Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the
CVE-2006-5051
<= 4.4
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly exe
8.1HIGH
CVE-2006-4924
all versions
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consu
CVE-2006-4315
all versions
Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and
CVE-2006-0883
all versions
OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM
CVE-2006-0225
all versions
scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, whi
CVE-2005-4310
all versions
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credent
CVE-2005-2798
all versions
sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who lo
CVE-2005-2797
all versions
OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address i
CVE-2005-2666
all versions
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintex
CVE-2005-2146
all versions
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secur
CVE-2004-2760
all versions
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the
CVE-2004-2069
all versions
sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the n
CVE-2004-1653
<= 3.9
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port b
CVE-2004-0175
all versions
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. N
CVE-2003-1562
all versions
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not
CVE-2003-1120
all versions
Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allo
CVE-2003-0787
all versions
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows
CVE-2003-0786
all versions
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check
CVE-2003-0695
<= 3.7.1
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary
CVE-2003-0682
<= 3.7.1
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-200
CVE-2003-0693
<= 3.7
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitr
CVE-2003-0386
all versions
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows rem
CVE-2003-0190
< 3.6.1
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not ex
CVE-2002-1715
all versions
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a
CVE-2002-1645
all versions
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to ex
CVE-2002-1644
all versions
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call
CVE-2002-0765
all versions
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and
CVE-2002-0640
all versions
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of re
CVE-2002-0639
>= 2.9.9 and <= 3.3
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response
9.8CRITICAL
CVE-2002-0575
all versions
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing
CVE-2002-0083
>= 2.0 and < 3.1
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privilege
9.8CRITICAL
CVE-2001-1585
all versions
SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 throu
CVE-2001-1507
all versions
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unc
CVE-2001-0872
<= 3.0.1
OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which
CVE-2001-0816
<= 2.9.9
OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypa
CVE-2001-1380
<= 2.9.9
OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not prope
CVE-2001-1382
<= 2.9.9p2
The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password
CVE-2001-1029
all versions
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright
CVE-2001-0572
all versions
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remot
CVE-2001-0529
<= 2.9
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symli
CVE-2001-0471
<= 1.2.30
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attac
CVE-2001-0364
all versions
SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simul
CVE-2001-0361
all versions
Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in
CVE-2001-1459
all versions
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, wh
CVE-2001-0259
all versions
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by anoth
CVE-2001-0144
all versions
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client
CVE-2001-1476
all versions
SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to gues
CVE-2001-1475
all versions
SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK)
CVE-2001-1474
all versions
SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect con
CVE-2001-1473
all versions
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target s
CVE-2001-1470
all versions
The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote att
CVE-2001-1469
all versions
The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message'
CVE-2000-1169
all versions
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gai
CVE-2000-0992
all versions
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a ..
CVE-2000-0999
all versions
Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root
CVE-2000-0575
all versions
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the
CVE-2000-0525
all versions
OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary comma
CVE-2000-0217
all versions
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a m
CVE-2000-0143
<= 1.2.1
The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the
CVE-1999-1010
all versions
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
CVE-1999-0787
all versions
The SSH authentication agent follows symlinks via a UNIX domain socket.
CVE-1999-1231
all versions
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only
CVE-1999-1029
all versions
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of
CVE-1999-0398
all versions
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
CVE-1999-0248
all versions
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
CVE-1999-1159
all versions
SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
CVE-1999-0310
all versions
SSH 1.2.25 on HP-UX allows access to new user accounts.
CVE-1999-0013
all versions
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the s
8.4HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin