- EPSS 4.85%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the co...
CVE-2004-2760
- EPSS 0.3%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for...
CVE-2004-1653
- EPSS 0.39%
- Veröffentlicht 31.08.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
CVE-2004-0175
- EPSS 0.39%
- Veröffentlicht 18.08.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.
CVE-2003-1562
- EPSS 0.8%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use t...
- EPSS 3.14%
- Veröffentlicht 17.11.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
CVE-2003-0787
- EPSS 0.46%
- Veröffentlicht 17.11.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.
CVE-2003-0682
- EPSS 0.33%
- Veröffentlicht 06.10.2003 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
CVE-2003-0695
- EPSS 1.02%
- Veröffentlicht 06.10.2003 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a differe...
- EPSS 26.82%
- Veröffentlicht 22.09.2003 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CV...