SSH
Ssh2: vulnerabilidades y CVE
Ssh2 tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2002-1715 | Alta (7.2) | 0.89% | — | 31 dic 2002 | SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell… |
| CVE-2002-1644 | Alta (7.2) | 0.45% | — | 25 nov 2002 | SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which… |
| CVE-2002-1645 | Alta (10) | 7.9% | — | 25 nov 2002 | Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL. |
| CVE-2001-0364 | Media (5) | 1.6% | — | 27 jun 2001 | SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections. |
| CVE-2000-0217 | Media (5.1) | 0.97% | — | 24 feb 2000 | The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program. |
| CVE-1999-1231 | Media (5) | 1.5% | — | 9 jun 1999 | ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to… |
| CVE-1999-1029 | Alta (7.5) | 1.6% | — | 13 may 1999 | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit… |
| CVE-1999-0398 | Media (4.6) | 0.39% | — | 1 ene 1999 | In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. |
| CVE-1999-1159 | Media (4.6) | 0.34% | — | 29 dic 1998 | SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root. |