Openbsd

Openssh

152 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 08.07.2026 00:07:07
  • Zuletzt bearbeitet 09.07.2026 17:14:27

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

  • EPSS 0.25%
  • Veröffentlicht 08.07.2026 00:04:49
  • Zuletzt bearbeitet 09.07.2026 17:14:47

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.06.2026 03:37:00
  • Zuletzt bearbeitet 24.09.2026 23:17:11

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators...

  • EPSS 0.09%
  • Veröffentlicht 23.06.2026 03:36:25
  • Zuletzt bearbeitet 07.10.2026 03:16:59

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 03:36:22
  • Zuletzt bearbeitet 07.10.2026 03:16:59

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when...

Medienbericht
  • EPSS 0.18%
  • Veröffentlicht 02.04.2026 17:08:15
  • Zuletzt bearbeitet 24.07.2026 21:10:00

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

  • EPSS 0.13%
  • Veröffentlicht 02.04.2026 16:57:31
  • Zuletzt bearbeitet 24.07.2026 21:10:00

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

  • EPSS 0.24%
  • Veröffentlicht 02.04.2026 16:52:53
  • Zuletzt bearbeitet 24.07.2026 21:10:00

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

  • EPSS 0.32%
  • Veröffentlicht 02.04.2026 16:44:27
  • Zuletzt bearbeitet 24.07.2026 21:10:00

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh...

  • EPSS 0.61%
  • Veröffentlicht 02.04.2026 16:30:59
  • Zuletzt bearbeitet 01.09.2026 13:19:01

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).