Записи libssh2
25 опубликованных записей вендора libssh2.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound6
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-354 Improper Validation of Integrity Check Value1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
25 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
38Наблюдать | CVE-2019-3855Эксплойта нет | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from libssh2 · libssh2 · CWE-190 | Высокая8,8 | — | 9,3 % | 21 мар. 2019 г. |
38Наблюдать | CVE-2019-3862Эксплойта нет | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message andlibssh2 · libssh2 · CWE-130 | Критическая9,1 | — | 7,9 % | 21 мар. 2019 г. |
38Наблюдать | CVE-2019-3858Эксплойта нет | An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server.libssh2 · libssh2 · CWE-125 | Критическая9,1 | — | 6,4 % | 21 мар. 2019 г. |
38Наблюдать | CVE-2019-3859Эксплойта нет | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions.libssh2 · libssh2 · CWE-125 | Критическая9,1 | — | 6,3 % | 21 мар. 2019 г. |
38Наблюдать | CVE-2019-3861Эксплойта нет | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packetlibssh2 · libssh2 · CWE-125 | Критическая9,1 | — | 5,1 % | 25 мар. 2019 г. |
38Наблюдать | CVE-2019-3860Эксплойта нет | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed.libssh2 · libssh2 · CWE-125 | Критическая9,1 | — | 5,1 % | 25 мар. 2019 г. |
37Наблюдать | CVE-2019-3857Эксплойта нет | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUESlibssh2 · libssh2 · CWE-190 | Высокая8,8 | — | 6,1 % | 25 мар. 2019 г. |
37Наблюдать | CVE-2019-3856Эксплойта нет | An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requlibssh2 · libssh2 · CWE-190 | Высокая8,8 | — | 6,1 % | 25 мар. 2019 г. |
36Наблюдать | CVE-2019-3863Эксплойта нет | A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side.libssh2 · libssh2 · CWE-190 | Высокая8,8 | — | 3,4 % | 25 мар. 2019 г. |
36Наблюдать | CVE-2026-55200Proof of concept | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.clibssh2 · libssh2 · CWE-680 | Критическая9,2 | — | 0,8 % | 17 июн. 2026 г. |
35Наблюдать | CVE-2019-13115Proof of concept | In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to anlibssh2 · libssh2 · CWE-125 | Высокая8,1 | — | 11,7 % | 16 июл. 2019 г. |
34Наблюдать | CVE-2026-66033Эксплойта нет | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiationlibssh2 · libssh2 · CWE-125 | Высокая8,7 | — | 0,7 % | 24 июл. 2026 г. |
34Наблюдать | CVE-2026-66032Эксплойта нет | libssh2 Double-Free Heap Corruption via sftp_open()libssh2 · libssh2 · CWE-415 | Высокая8,7 | — | 0,4 % | 24 июл. 2026 г. |
33Наблюдать | CVE-2019-17498Proof of concept | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attalibssh2 · libssh2 · CWE-190 | Высокая8,1 | — | 3,8 % | 21 окт. 2019 г. |
33Наблюдать | CVE-2025-15661Эксплойта нет | libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.clibssh2 · libssh2 · CWE-125 | Высокая8,3 | — | 0,6 % | 18 июн. 2026 г. |
33Наблюдать | CVE-2026-58050Эксплойта нет | libssh2 - Integer Overflow in publickey Subsystem Attribute Allocationlibssh2 · libssh2 · CWE-190 | Высокая8,3 | — | 0,4 % | 27 июн. 2026 г. |
33Наблюдать | CVE-2026-58051Эксплойта нет | libssh2 - Free of Uninitialized Pointer in publickey List Cleanuplibssh2 · libssh2 · CWE-908 | Высокая8,3 | — | 0,3 % | 27 июн. 2026 г. |
32Наблюдать | CVE-2026-55199Эксплойта нет | libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handlerlibssh2 · libssh2 · CWE-835 | Высокая8,2 | — | 0,7 % | 17 июн. 2026 г. |
30Наблюдать | CVE-2020-22218Эксплойта нет | An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.libssh2 · libssh2 · CWE-787 | Высокая7,5 | — | 1,1 % | 22 авг. 2023 г. |
30Наблюдать | CVE-2026-66035Эксплойта нет | libssh2 Heap Buffer Overflow via ETM Cipher Negotiationlibssh2 · libssh2 · CWE-122 | Высокая7,7 | — | 0,6 % | 24 июл. 2026 г. |
30Наблюдать | CVE-2026-66034Эксплойта нет | libssh2 Heap Out-of-Bounds Read via publickey subsystemlibssh2 · libssh2 · CWE-125 | Высокая7,7 | — | 0,4 % | 24 июл. 2026 г. |
28Наблюдать | CVE-2015-1782Эксплойта нет | The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified libssh2 · libssh2 · CWE-20 | Средняя6,8 | — | 3,5 % | 13 мар. 2015 г. |
27Наблюдать | CVE-2026-7598Эксплойта нет | libssh2 userauth.c userauth_password integer overflowlibssh2 · libssh2 · CWE-189 | Средняя6,9 | — | 0,8 % | 1 мая 2026 г. |
24Наблюдать | CVE-2016-0787Эксплойта нет | The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier flibssh2 · libssh2 · CWE-200 | Средняя5,9 | — | 2,6 % | 13 апр. 2016 г. |
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2019-385538Наблюдать
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from
ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %libssh2 · libssh221 мар. 2019 г.
- CVE-2019-386238Наблюдать
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and
КритическаяCVSS 9,1Эксплойта нетEPSS 8 %libssh2 · libssh221 мар. 2019 г.
- CVE-2019-385838Наблюдать
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server.
КритическаяCVSS 9,1Эксплойта нетEPSS 6 %libssh2 · libssh221 мар. 2019 г.
- CVE-2019-385938Наблюдать
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions.
КритическаяCVSS 9,1Эксплойта нетEPSS 6 %libssh2 · libssh221 мар. 2019 г.
- CVE-2019-386138Наблюдать
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet
КритическаяCVSS 9,1Эксплойта нетEPSS 5 %libssh2 · libssh225 мар. 2019 г.
- CVE-2019-386038Наблюдать
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed.
КритическаяCVSS 9,1Эксплойта нетEPSS 5 %libssh2 · libssh225 мар. 2019 г.
- CVE-2019-385737Наблюдать
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUES
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %libssh2 · libssh225 мар. 2019 г.
- CVE-2019-385637Наблюдать
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requ
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %libssh2 · libssh225 мар. 2019 г.
- CVE-2019-386336Наблюдать
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %libssh2 · libssh225 мар. 2019 г.
- CVE-2026-5520036Наблюдать
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
КритическаяCVSS 9,2Proof of conceptEPSS 1 %libssh2 · libssh217 июн. 2026 г.
- CVE-2019-1311535Наблюдать
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an
ВысокаяCVSS 8,1Proof of conceptEPSS 12 %libssh2 · libssh216 июл. 2019 г.
- CVE-2026-6603334Наблюдать
libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %libssh2 · libssh224 июл. 2026 г.
- CVE-2026-6603234Наблюдать
libssh2 Double-Free Heap Corruption via sftp_open()
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %libssh2 · libssh224 июл. 2026 г.
- CVE-2019-1749833Наблюдать
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an atta
ВысокаяCVSS 8,1Proof of conceptEPSS 4 %libssh2 · libssh221 окт. 2019 г.
- CVE-2025-1566133Наблюдать
libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %libssh2 · libssh218 июн. 2026 г.
- CVE-2026-5805033Наблюдать
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %libssh2 · libssh227 июн. 2026 г.
- CVE-2026-5805133Наблюдать
libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %libssh2 · libssh227 июн. 2026 г.
- CVE-2026-5519932Наблюдать
libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %libssh2 · libssh217 июн. 2026 г.
- CVE-2020-2221830Наблюдать
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %libssh2 · libssh222 авг. 2023 г.
- CVE-2026-6603530Наблюдать
libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %libssh2 · libssh224 июл. 2026 г.
- CVE-2026-6603430Наблюдать
libssh2 Heap Out-of-Bounds Read via publickey subsystem
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %libssh2 · libssh224 июл. 2026 г.
- CVE-2015-178228Наблюдать
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified
СредняяCVSS 6,8Эксплойта нетEPSS 4 %libssh2 · libssh213 мар. 2015 г.
- CVE-2026-759827Наблюдать
libssh2 userauth.c userauth_password integer overflow
СредняяCVSS 6,9Эксплойта нетEPSS 1 %libssh2 · libssh21 мая 2026 г.
- CVE-2016-078724Наблюдать
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier f
СредняяCVSS 5,9Эксплойта нетEPSS 3 %libssh2 · libssh213 апр. 2016 г.