Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ssh vulnerabilities and exploits
(subscribe to this query)
4.4
CVSSv2
CVE-2021-44512
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local malicious user to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
Tmate Tmate-ssh-server
4.4
CVSSv2
CVE-2021-44513
Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local malicious user to compromise the integrity of session handling.
Tmate Tmate-ssh-server
5
CVSSv2
CVE-2009-1273
pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote malicious users to enumerate usernames.
Andrew J.korty Pam Ssh 1.92
7.8
CVSSv2
CVE-2008-0534
The SSH server in (1) Cisco Service Control Engine (SCE) prior to 3.1.6, and (2) Icon Labs Iconfidant SSH prior to 2.3.8, allows remote malicious users to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582.
Cisco Service Control Engine
Icon-labs Iconfidant Ssh
7.8
CVSSv2
CVE-2008-0535
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) prior to 3.1.6, and (2) Icon Labs Iconfidant SSH prior to 2.3.8, allows remote malicious users to cause a denial of service (device instability) via "SSH credentials that attempt to change ...
Cisco Service Control Engine
Icon-labs Iconfidant Ssh
6.9
CVSSv2
CVE-2021-1572
A vulnerability in ConfD could allow an authenticated, local malicious user to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an attacker must have a valid account on an affected device. ...
Cisco Confd
Cisco Network Services Orchestrator
5
CVSSv2
CVE-2020-9283
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.
Golang Package Ssh 0.0.0-20200220183623-bac4c82f6975
Debian Debian Linux 9.0
1 EDB exploit
3 Github repositories
7.1
CVSSv2
CVE-2005-1021
Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 up to and including 12.3, when authenticating against a TACACS+ server, allows remote malicious users to cause a denial of service (memory consumption) via an incorrect username or password.
Cisco Ios 12.1xg
Cisco Ios 12.3xr
Cisco Ios 12.1xm
Cisco Ios 12.1xi
Cisco Ios 12.1e
Cisco Ios 12.3ya
Cisco Ios 12.1xp
Cisco Ios 12.1ya
Cisco Ios 12.1yd
Cisco Ios 12.3xs
Cisco Ios 12.2sx
Cisco Ios 12.3xg
Cisco Ios 12.3xd
Cisco Ios 12.3xm
Cisco Ios 12.3xw
Cisco Ios 12.2su
Cisco Ios 12.2ew
Cisco Ios 12.2b
Cisco Ios 12.2sea
Cisco Ios 12.1t
Cisco Ios 12.3xi
Cisco Ios 12.1xr
7.8
CVSSv2
CVE-2008-0536
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x prior to 3.0.7 and 3.1.x prior to 3.1.0, and (2) Icon Labs Iconfidant SSH prior to 2.3.8, allows remote malicious users to cause a denial of service (management interface outage) via SSH t...
Cisco Service Control Engine 3.0
Cisco Service Control Engine
Icon-labs Iconfidant Ssh
NA
CVE-2023-48795
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH prior to 9.6 and other products, allows remote malicious users to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may conseque...
Openbsd Openssh
Putty Putty
Filezilla-project Filezilla Client
Microsoft Powershell
Panic Transmit 5
Panic Nova
Roumenpetrov Pkixssh
Winscp Winscp
Bitvise Ssh Client
Bitvise Ssh Server
Lancom-systems Lcos
Lancom-systems Lcos Fx -
Lancom-systems Lcos Lx -
Lancom-systems Lcos Sx 5.20
Lancom-systems Lcos Sx 4.20
Lancom-systems Lanconfig -
Vandyke Securecrt
Libssh Libssh
Net-ssh Net-ssh 7.2.0
Ssh2 Project Ssh2
Proftpd Proftpd
Freebsd Freebsd
9 Github repositories
1 Article
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »