Skip to content
Noroxi

SSH records

47 published records for vendor ssh.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 4.3%
Pre-auth RCE
2
With a fix record
8.5%
Median publish → KEV
No record has entered KEV

All records

47 records
  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 94%

    ssh · sshDec 18, 2023

  • CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in

    CriticalCVSS 10.0Proof of conceptEPSS 32%

    ssh · sshMar 12, 2001

  • The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 thro

    CriticalCVSS 9.3WeaponizedEPSS 36%

    ssh · tectia serverDec 4, 2012

  • Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbi

    CriticalCVSS 10.0No exploitEPSS 8%

    ssh · ssh2Nov 25, 2002

  • A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.

    CriticalCVSS 10.0No exploitEPSS 2%

    ssh · sshJan 1, 1999

  • PrivX before 34.0 allows data exfiltration and denial of service via the REST API.

    CriticalCVSS 9.1No exploitEPSS 1%

    ssh · privxAug 6, 2024

  • SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.

    HighCVSS 8.8No exploitEPSS 1%

    ssh · tectia clientMar 15, 2021

  • CVE-1999-0013
    33Monitor

    Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent u

    HighCVSS 8.4No exploitEPSS 1%

    ssh · sshJan 22, 1998

  • CVE-2001-0572
    32Monitor

    The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker

    HighCVSS 7.5No exploitEPSS 7%

    ssh · sshAug 22, 2001

  • CVE-2001-1473
    32Monitor

    The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by c

    HighCVSS 7.5Proof of conceptEPSS 6%

    ssh · sshJan 18, 2001

  • CVE-2001-0471
    32Monitor

    SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to co

    HighCVSS 7.5Proof of conceptEPSS 6%

    ssh · sshJun 27, 2001

  • CVE-2011-0766
    32Monitor

    The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14

    HighCVSS 7.8No exploitEPSS 3%

    erlang · cryptoMay 31, 2011

  • CVE-2002-1646
    31Monitor

    SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure

    HighCVSS 7.5No exploitEPSS 4%

    ssh · secure shell for serversDec 31, 2002

  • SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.

    HighCVSS 7.8No exploitEPSS 0%

    ssh · tectia clientMar 15, 2021

  • CVE-1999-1029
    30Monitor

    SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, all

    HighCVSS 7.5No exploitEPSS 2%

    ssh · ssh2May 13, 1999

  • CVE-2001-1475
    30Monitor

    SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is genera

    HighCVSS 7.5No exploitEPSS 2%

    ssh · sshJan 18, 2001

  • CVE-1999-0310
    30Monitor

    SSH 1.2.25 on HP-UX allows access to new user accounts.

    HighCVSS 7.5No exploitEPSS 2%

    ssh · sshSep 1, 1998

  • CVE-2005-4310
    30Monitor

    SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.

    HighCVSS 7.5No exploitEPSS 1%

    ssh · tectia serverDec 16, 2005

  • CVE-2001-1476
    30Monitor

    SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions

    HighCVSS 7.5No exploitEPSS 1%

    ssh · sshJan 18, 2001

  • CVE-2001-0553
    28Monitor

    SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to ga

    HighCVSS 7.2Proof of conceptEPSS 1%

    ssh · secure shellAug 14, 2001

  • CVE-2007-5616
    28Monitor

    ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges

    HighCVSS 7.2No exploitEPSS 1%

    ssh · tectia clientJan 9, 2008

  • CVE-2002-1715
    28Monitor

    SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to

    HighCVSS 7.2Proof of conceptEPSS 1%

    ssh · sshDec 31, 2002

  • CVE-2000-0575
    28Monitor

    SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who

    HighCVSS 7.2No exploitEPSS 1%

    ssh · sshJul 5, 2000

  • CVE-2002-1644
    28Monitor

    SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to

    HighCVSS 7.2No exploitEPSS 0%

    ssh · ssh2Nov 25, 2002

  • SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.

    HighCVSS 7.0No exploitEPSS 0%

    ssh · tectia clientMar 15, 2021