Skip to content
Noroxi

libssh records

45 published records for vendor libssh.

All records

45 records
  • CVE-2018-10933
    64This week

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.

    CriticalCVSS 9.1WeaponizedEPSS 92%

    libssh · libsshOct 17, 2018

  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 94%

    ssh · sshDec 18, 2023

  • A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8.

    HighCVSS 8.8No exploitEPSS 3%

    libssh · libsshDec 10, 2019

  • Libssh: libssh: authentication bypass via missing gssapi principal check

    HighCVSS 8.8No exploitEPSS 0%

    libssh · libsshJul 21, 2026

  • CVE-2025-5372
    35Monitor

    Libssh: incorrect return code handling in ssh_kdf() in libssh

    HighCVSS 8.8No exploitEPSS 0%

    libssh · libsshJul 4, 2025

  • CVE-2012-4562
    34Monitor

    Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly

    HighCVSS 7.5No exploitEPSS 13%

    libssh · libsshNov 30, 2012

  • CVE-2012-4560
    32Monitor

    Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary c

    HighCVSS 7.5No exploitEPSS 6%

    libssh · libsshNov 30, 2012

  • CVE-2025-5987
    32Monitor

    Libssh: invalid return code for chacha20 poly1305 with openssl backend

    HighCVSS 8.1No exploitEPSS 2%

    libssh · libsshJul 7, 2025

  • CVE-2026-0966
    32Monitor

    Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()

    HighCVSS 8.2No exploitEPSS 1%

    libssh · libsshMar 26, 2026

  • CVE-2015-3146
    31Monitor

    The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, w

    HighCVSS 7.5No exploitEPSS 4%

    libssh · libsshApr 13, 2016

  • CVE-2012-6063
    31Monitor

    Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (

    HighCVSS 7.5No exploitEPSS 4%

    libssh · libsshNov 30, 2012

  • Libssh: libssh: use-after-free via data callbacks on closed channels

    HighCVSS 7.5No exploitEPSS 1%

    libssh · libsshJul 21, 2026

  • Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification

    HighCVSS 7.5No exploitEPSS 1%

    libssh · libsshJul 21, 2026

  • Libssh: libssh: denial of service via automatic certificate authentication loop

    HighCVSS 7.5No exploitEPSS 0%

    libssh · libsshJul 21, 2026

  • CVE-2012-4559
    29Monitor

    Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_use

    MediumCVSS 6.8No exploitEPSS 5%

    libssh · libsshNov 30, 2012

  • Libssh: libssh: stack buffer overflow in sftp server longname construction

    HighCVSS 7.3No exploitEPSS 0%

    libssh · libsshJul 21, 2026

  • Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

    HighCVSS 7.0No exploitEPSS 0%

    libssh · libsshApr 7, 2026

  • CVE-2021-3634
    27Monitor

    A flaw has been found in libssh in versions prior to 0.9.6.

    MediumCVSS 6.5No exploitEPSS 5%

    libssh · libsshAug 31, 2021

  • CVE-2026-3731
    27Monitor

    libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds

    MediumCVSS 6.9No exploitEPSS 1%

    libssh · libsshMar 8, 2026

  • CVE-2023-1667
    26Monitor

    A NULL pointer dereference was found In libssh during re-keying with algorithm guessing.

    MediumCVSS 6.5No exploitEPSS 1%

    libssh · libsshMay 26, 2023

  • CVE-2023-2283
    26Monitor

    A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signatur

    MediumCVSS 6.5No exploitEPSS 1%

    libssh · libsshMay 26, 2023

  • CVE-2023-3603
    26Monitor

    Processing sftp server read may cause null dereference

    MediumCVSS 6.5No exploitEPSS 1%

    libssh · libsshJul 21, 2023

  • CVE-2025-5449
    26Monitor

    Libssh: integer overflow in libssh sftp server packet length validation leading to denial of service

    MediumCVSS 6.5No exploitEPSS 1%

    libssh · libsshJul 25, 2025

  • Libssh: libssh: denial of service via zero advertised channel packet size

    MediumCVSS 6.5No exploitEPSS 1%

    libssh · libsshJul 21, 2026

  • Libssh: libssh: denial of service via oversized sftp read length

    MediumCVSS 6.5No exploitEPSS 1%

    libssh · libsshJul 21, 2026