Openbsd

Openssh

152 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 2.18%
  • Veröffentlicht 12.03.2026 18:27:44
  • Zuletzt bearbeitet 15.07.2026 02:21:00

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconn...

  • EPSS 0.28%
  • Veröffentlicht 06.10.2025 00:00:00
  • Zuletzt bearbeitet 14.07.2026 13:17:56

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence exp...

  • EPSS 0.11%
  • Veröffentlicht 06.10.2025 00:00:00
  • Zuletzt bearbeitet 14.07.2026 13:17:57

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

  • EPSS 0.19%
  • Veröffentlicht 10.04.2025 00:00:00
  • Zuletzt bearbeitet 22.05.2025 16:51:54

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

Medienbericht
  • EPSS 39.85%
  • Veröffentlicht 28.02.2025 22:15:40
  • Zuletzt bearbeitet 08.10.2026 12:17:13

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious cli...

Medienbericht
  • EPSS 7.45%
  • Veröffentlicht 18.02.2025 19:15:29
  • Zuletzt bearbeitet 02.09.2026 02:17:18

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...

  • EPSS 27.94%
  • Veröffentlicht 08.07.2024 18:15:09
  • Zuletzt bearbeitet 21.08.2026 13:16:25

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handl...

  • EPSS 1.63%
  • Veröffentlicht 02.07.2024 18:15:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

Medienbericht Exploit
  • EPSS 99.51%
  • Veröffentlicht 01.07.2024 13:15:06
  • Zuletzt bearbeitet 01.09.2026 12:17:13

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 24.12.2023 07:15:07
  • Zuletzt bearbeitet 02.06.2026 16:16:28

OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable ...