libssh2 kayıtları
libssh2 üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound6
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-354 Improper Validation of Integrity Check Value1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
38İzleyin | CVE-2019-3855İstismar yok | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from libssh2 · libssh2 · CWE-190 | Yüksek8,8 | — | %9,3 | 21 Mar 2019 |
38İzleyin | CVE-2019-3862İstismar yok | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message andlibssh2 · libssh2 · CWE-130 | Kritik9,1 | — | %7,9 | 21 Mar 2019 |
38İzleyin | CVE-2019-3858İstismar yok | An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server.libssh2 · libssh2 · CWE-125 | Kritik9,1 | — | %6,4 | 21 Mar 2019 |
38İzleyin | CVE-2019-3859İstismar yok | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions.libssh2 · libssh2 · CWE-125 | Kritik9,1 | — | %6,3 | 21 Mar 2019 |
38İzleyin | CVE-2019-3861İstismar yok | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packetlibssh2 · libssh2 · CWE-125 | Kritik9,1 | — | %5,1 | 25 Mar 2019 |
38İzleyin | CVE-2019-3860İstismar yok | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed.libssh2 · libssh2 · CWE-125 | Kritik9,1 | — | %5,1 | 25 Mar 2019 |
37İzleyin | CVE-2019-3857İstismar yok | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUESlibssh2 · libssh2 · CWE-190 | Yüksek8,8 | — | %6,1 | 25 Mar 2019 |
37İzleyin | CVE-2019-3856İstismar yok | An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requlibssh2 · libssh2 · CWE-190 | Yüksek8,8 | — | %6,1 | 25 Mar 2019 |
36İzleyin | CVE-2019-3863İstismar yok | A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side.libssh2 · libssh2 · CWE-190 | Yüksek8,8 | — | %3,4 | 25 Mar 2019 |
36İzleyin | CVE-2026-55200Kavram kanıtı | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.clibssh2 · libssh2 · CWE-680 | Kritik9,2 | — | %0,8 | 17 Haz 2026 |
35İzleyin | CVE-2019-13115Kavram kanıtı | In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to anlibssh2 · libssh2 · CWE-125 | Yüksek8,1 | — | %11,7 | 16 Tem 2019 |
34İzleyin | CVE-2026-66033İstismar yok | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiationlibssh2 · libssh2 · CWE-125 | Yüksek8,7 | — | %0,7 | 24 Tem 2026 |
34İzleyin | CVE-2026-66032İstismar yok | libssh2 Double-Free Heap Corruption via sftp_open()libssh2 · libssh2 · CWE-415 | Yüksek8,7 | — | %0,4 | 24 Tem 2026 |
33İzleyin | CVE-2019-17498Kavram kanıtı | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attalibssh2 · libssh2 · CWE-190 | Yüksek8,1 | — | %3,8 | 21 Eki 2019 |
33İzleyin | CVE-2025-15661İstismar yok | libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.clibssh2 · libssh2 · CWE-125 | Yüksek8,3 | — | %0,6 | 18 Haz 2026 |
33İzleyin | CVE-2026-58050İstismar yok | libssh2 - Integer Overflow in publickey Subsystem Attribute Allocationlibssh2 · libssh2 · CWE-190 | Yüksek8,3 | — | %0,4 | 27 Haz 2026 |
33İzleyin | CVE-2026-58051İstismar yok | libssh2 - Free of Uninitialized Pointer in publickey List Cleanuplibssh2 · libssh2 · CWE-908 | Yüksek8,3 | — | %0,3 | 27 Haz 2026 |
32İzleyin | CVE-2026-55199İstismar yok | libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handlerlibssh2 · libssh2 · CWE-835 | Yüksek8,2 | — | %0,7 | 17 Haz 2026 |
30İzleyin | CVE-2020-22218İstismar yok | An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.libssh2 · libssh2 · CWE-787 | Yüksek7,5 | — | %1,1 | 22 Ağu 2023 |
30İzleyin | CVE-2026-66035İstismar yok | libssh2 Heap Buffer Overflow via ETM Cipher Negotiationlibssh2 · libssh2 · CWE-122 | Yüksek7,7 | — | %0,6 | 24 Tem 2026 |
30İzleyin | CVE-2026-66034İstismar yok | libssh2 Heap Out-of-Bounds Read via publickey subsystemlibssh2 · libssh2 · CWE-125 | Yüksek7,7 | — | %0,4 | 24 Tem 2026 |
28İzleyin | CVE-2015-1782İstismar yok | The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified libssh2 · libssh2 · CWE-20 | Orta6,8 | — | %3,5 | 13 Mar 2015 |
27İzleyin | CVE-2026-7598İstismar yok | libssh2 userauth.c userauth_password integer overflowlibssh2 · libssh2 · CWE-189 | Orta6,9 | — | %0,8 | 1 May 2026 |
24İzleyin | CVE-2016-0787İstismar yok | The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier flibssh2 · libssh2 · CWE-200 | Orta5,9 | — | %2,6 | 13 Nis 2016 |
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2019-385538İzleyin
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from
YüksekCVSS 8,8İstismar yokEPSS %9libssh2 · libssh221 Mar 2019
- CVE-2019-386238İzleyin
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and
KritikCVSS 9,1İstismar yokEPSS %8libssh2 · libssh221 Mar 2019
- CVE-2019-385838İzleyin
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server.
KritikCVSS 9,1İstismar yokEPSS %6libssh2 · libssh221 Mar 2019
- CVE-2019-385938İzleyin
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions.
KritikCVSS 9,1İstismar yokEPSS %6libssh2 · libssh221 Mar 2019
- CVE-2019-386138İzleyin
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet
KritikCVSS 9,1İstismar yokEPSS %5libssh2 · libssh225 Mar 2019
- CVE-2019-386038İzleyin
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed.
KritikCVSS 9,1İstismar yokEPSS %5libssh2 · libssh225 Mar 2019
- CVE-2019-385737İzleyin
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUES
YüksekCVSS 8,8İstismar yokEPSS %6libssh2 · libssh225 Mar 2019
- CVE-2019-385637İzleyin
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requ
YüksekCVSS 8,8İstismar yokEPSS %6libssh2 · libssh225 Mar 2019
- CVE-2019-386336İzleyin
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side.
YüksekCVSS 8,8İstismar yokEPSS %3libssh2 · libssh225 Mar 2019
- CVE-2026-5520036İzleyin
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
KritikCVSS 9,2Kavram kanıtıEPSS %1libssh2 · libssh217 Haz 2026
- CVE-2019-1311535İzleyin
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an
YüksekCVSS 8,1Kavram kanıtıEPSS %12libssh2 · libssh216 Tem 2019
- CVE-2026-6603334İzleyin
libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
YüksekCVSS 8,7İstismar yokEPSS %1libssh2 · libssh224 Tem 2026
- CVE-2026-6603234İzleyin
libssh2 Double-Free Heap Corruption via sftp_open()
YüksekCVSS 8,7İstismar yokEPSS %0libssh2 · libssh224 Tem 2026
- CVE-2019-1749833İzleyin
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an atta
YüksekCVSS 8,1Kavram kanıtıEPSS %4libssh2 · libssh221 Eki 2019
- CVE-2025-1566133İzleyin
libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
YüksekCVSS 8,3İstismar yokEPSS %1libssh2 · libssh218 Haz 2026
- CVE-2026-5805033İzleyin
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
YüksekCVSS 8,3İstismar yokEPSS %0libssh2 · libssh227 Haz 2026
- CVE-2026-5805133İzleyin
libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
YüksekCVSS 8,3İstismar yokEPSS %0libssh2 · libssh227 Haz 2026
- CVE-2026-5519932İzleyin
libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
YüksekCVSS 8,2İstismar yokEPSS %1libssh2 · libssh217 Haz 2026
- CVE-2020-2221830İzleyin
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.
YüksekCVSS 7,5İstismar yokEPSS %1libssh2 · libssh222 Ağu 2023
- CVE-2026-6603530İzleyin
libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
YüksekCVSS 7,7İstismar yokEPSS %1libssh2 · libssh224 Tem 2026
- CVE-2026-6603430İzleyin
libssh2 Heap Out-of-Bounds Read via publickey subsystem
YüksekCVSS 7,7İstismar yokEPSS %0libssh2 · libssh224 Tem 2026
- CVE-2015-178228İzleyin
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified
OrtaCVSS 6,8İstismar yokEPSS %4libssh2 · libssh213 Mar 2015
- CVE-2026-759827İzleyin
libssh2 userauth.c userauth_password integer overflow
OrtaCVSS 6,9İstismar yokEPSS %1libssh2 · libssh21 May 2026
- CVE-2016-078724İzleyin
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier f
OrtaCVSS 5,9İstismar yokEPSS %3libssh2 · libssh213 Nis 2016