ssh kayıtları
ssh üreticisine ait 47 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %4,3
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %8,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-310 Cryptographic Issues3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
47 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,3 | 18 Ara 2023 |
50Planlayın | CVE-2001-0144Kavram kanıtı | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an inssh · ssh | Kritik10,0 | — | %32,4 | 12 Mar 2001 |
48Planlayın | CVE-2012-5975Silahlaştırılmış | The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 throssh · tectia server · CWE-287 | Kritik9,3 | — | %35,9 | 4 Ara 2012 |
42Planlayın | CVE-2002-1645İstismar yok | Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbissh · ssh2 | Kritik10,0 | — | %7,9 | 25 Kas 2002 |
40Planlayın | CVE-1999-0248İstismar yok | A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.ssh · ssh | Kritik10,0 | — | %1,6 | 1 Oca 1999 |
36İzleyin | CVE-2024-30170İstismar yok | PrivX before 34.0 allows data exfiltration and denial of service via the REST API.ssh · privx · CWE-400 | Kritik9,1 | — | %0,6 | 6 Ağu 2024 |
35İzleyin | CVE-2021-27891İstismar yok | SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.ssh · tectia client | Yüksek8,8 | — | %1,0 | 15 Mar 2021 |
33İzleyin | CVE-1999-0013İstismar yok | Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent ussh · ssh · CWE-522 | Yüksek8,4 | — | %1,1 | 22 Oca 1998 |
32İzleyin | CVE-2001-0572İstismar yok | The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attackerssh · ssh | Yüksek7,5 | — | %7,1 | 22 Ağu 2001 |
32İzleyin | CVE-2001-1473Kavram kanıtı | The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by cssh · ssh · CWE-310 | Yüksek7,5 | — | %6,3 | 18 Oca 2001 |
32İzleyin | CVE-2001-0471Kavram kanıtı | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to cossh · ssh | Yüksek7,5 | — | %5,6 | 27 Haz 2001 |
32İzleyin | CVE-2011-0766İstismar yok | The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14erlang · crypto · CWE-310 | Yüksek7,8 | — | %3,1 | 31 May 2011 |
31İzleyin | CVE-2002-1646İstismar yok | SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less securessh · secure shell for servers | Yüksek7,5 | — | %3,6 | 31 Ara 2002 |
31İzleyin | CVE-2021-27892İstismar yok | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.ssh · tectia client | Yüksek7,8 | — | %0,3 | 15 Mar 2021 |
30İzleyin | CVE-1999-1029İstismar yok | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allssh · ssh2 | Yüksek7,5 | — | %1,6 | 13 May 1999 |
30İzleyin | CVE-2001-1475İstismar yok | SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generassh · ssh | Yüksek7,5 | — | %1,5 | 18 Oca 2001 |
30İzleyin | CVE-1999-0310İstismar yok | SSH 1.2.25 on HP-UX allows access to new user accounts.ssh · ssh | Yüksek7,5 | — | %1,5 | 1 Eyl 1998 |
30İzleyin | CVE-2005-4310İstismar yok | SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.ssh · tectia server | Yüksek7,5 | — | %1,4 | 16 Ara 2005 |
30İzleyin | CVE-2001-1476İstismar yok | SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portionsssh · ssh | Yüksek7,5 | — | %1,0 | 18 Oca 2001 |
28İzleyin | CVE-2001-0553Kavram kanıtı | SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gassh · secure shell | Yüksek7,2 | — | %1,3 | 14 Ağu 2001 |
28İzleyin | CVE-2007-5616İstismar yok | ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privilegesssh · tectia client | Yüksek7,2 | — | %0,9 | 9 Oca 2008 |
28İzleyin | CVE-2002-1715Kavram kanıtı | SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to ssh · ssh | Yüksek7,2 | — | %0,9 | 31 Ara 2002 |
28İzleyin | CVE-2000-0575İstismar yok | SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who ssh · ssh | Yüksek7,2 | — | %0,8 | 5 Tem 2000 |
28İzleyin | CVE-2002-1644İstismar yok | SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid tossh · ssh2 | Yüksek7,2 | — | %0,4 | 25 Kas 2002 |
28İzleyin | CVE-2021-27893İstismar yok | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.ssh · tectia client | Yüksek7,0 | — | %0,4 | 15 Mar 2021 |
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %93ssh · ssh18 Ara 2023
- CVE-2001-014450Planlayın
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in
KritikCVSS 10,0Kavram kanıtıEPSS %32ssh · ssh12 Mar 2001
- CVE-2012-597548Planlayın
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 thro
KritikCVSS 9,3SilahlaştırılmışEPSS %36ssh · tectia server4 Ara 2012
- CVE-2002-164542Planlayın
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbi
KritikCVSS 10,0İstismar yokEPSS %8ssh · ssh225 Kas 2002
- CVE-1999-024840Planlayın
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
KritikCVSS 10,0İstismar yokEPSS %2ssh · ssh1 Oca 1999
- CVE-2024-3017036İzleyin
PrivX before 34.0 allows data exfiltration and denial of service via the REST API.
KritikCVSS 9,1İstismar yokEPSS %1ssh · privx6 Ağu 2024
- CVE-2021-2789135İzleyin
SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.
YüksekCVSS 8,8İstismar yokEPSS %1ssh · tectia client15 Mar 2021
- CVE-1999-001333İzleyin
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent u
YüksekCVSS 8,4İstismar yokEPSS %1ssh · ssh22 Oca 1998
- CVE-2001-057232İzleyin
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker
YüksekCVSS 7,5İstismar yokEPSS %7ssh · ssh22 Ağu 2001
- CVE-2001-147332İzleyin
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by c
YüksekCVSS 7,5Kavram kanıtıEPSS %6ssh · ssh18 Oca 2001
- CVE-2001-047132İzleyin
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to co
YüksekCVSS 7,5Kavram kanıtıEPSS %6ssh · ssh27 Haz 2001
- CVE-2011-076632İzleyin
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14
YüksekCVSS 7,8İstismar yokEPSS %3erlang · crypto31 May 2011
- CVE-2002-164631İzleyin
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure
YüksekCVSS 7,5İstismar yokEPSS %4ssh · secure shell for servers31 Ara 2002
- CVE-2021-2789231İzleyin
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.
YüksekCVSS 7,8İstismar yokEPSS %0ssh · tectia client15 Mar 2021
- CVE-1999-102930İzleyin
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, all
YüksekCVSS 7,5İstismar yokEPSS %2ssh · ssh213 May 1999
- CVE-2001-147530İzleyin
SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is genera
YüksekCVSS 7,5İstismar yokEPSS %2ssh · ssh18 Oca 2001
- CVE-1999-031030İzleyin
SSH 1.2.25 on HP-UX allows access to new user accounts.
YüksekCVSS 7,5İstismar yokEPSS %2ssh · ssh1 Eyl 1998
- CVE-2005-431030İzleyin
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.
YüksekCVSS 7,5İstismar yokEPSS %1ssh · tectia server16 Ara 2005
- CVE-2001-147630İzleyin
SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions
YüksekCVSS 7,5İstismar yokEPSS %1ssh · ssh18 Oca 2001
- CVE-2001-055328İzleyin
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to ga
YüksekCVSS 7,2Kavram kanıtıEPSS %1ssh · secure shell14 Ağu 2001
- CVE-2007-561628İzleyin
ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges
YüksekCVSS 7,2İstismar yokEPSS %1ssh · tectia client9 Oca 2008
- CVE-2002-171528İzleyin
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to
YüksekCVSS 7,2Kavram kanıtıEPSS %1ssh · ssh31 Ara 2002
- CVE-2000-057528İzleyin
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who
YüksekCVSS 7,2İstismar yokEPSS %1ssh · ssh5 Tem 2000
- CVE-2002-164428İzleyin
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to
YüksekCVSS 7,2İstismar yokEPSS %0ssh · ssh225 Kas 2002
- CVE-2021-2789328İzleyin
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.
YüksekCVSS 7,0İstismar yokEPSS %0ssh · tectia client15 Mar 2021