- EPSS 1.81%
- Veröffentlicht 10.02.2011 18:00:57
- Zuletzt bearbeitet 16.06.2026 23:27:35
The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stac...
CVE-2010-4478
- EPSS 4.24%
- Veröffentlicht 06.12.2010 22:30:31
- Zuletzt bearbeitet 16.06.2026 23:24:53
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending c...
CVE-2009-2904
- EPSS 0.32%
- Veröffentlicht 01.10.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:28
A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use config...
CVE-2008-5161
- EPSS 15.4%
- Veröffentlicht 19.11.2008 17:30:00
- Zuletzt bearbeitet 16.06.2026 22:59:22
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server f...
- EPSS 28.6%
- Veröffentlicht 18.09.2008 15:04:27
- Zuletzt bearbeitet 16.06.2026 22:57:11
A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attac...
CVE-2008-3844
- EPSS 2.66%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:39
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact....
CVE-2008-3259
- EPSS 0.33%
- Veröffentlicht 22.07.2008 16:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:29
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the ...
CVE-2008-3234
- EPSS 5.77%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:26
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.
CVE-2008-1657
- EPSS 2.21%
- Veröffentlicht 02.04.2008 18:44:00
- Zuletzt bearbeitet 16.06.2026 22:52:11
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
CVE-2008-1483
- EPSS 0.35%
- Veröffentlicht 24.03.2008 23:44:00
- Zuletzt bearbeitet 16.06.2026 22:51:49
OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and ...