Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 6.4% | — | Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1 | 21/3/2019 | 17/6/2026 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | |
| Modificada | Alta (8.8) | 9.3% | — | Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+10 | 21/3/2019 | 17/6/2026 | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server. | |
| Modificada | Crítica (9.1) | 7.9% | — | Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1 | 21/3/2019 | 17/6/2026 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | |
| Modificada | Crítica (9.1) | 6.3% | — | Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1 | 21/3/2019 | 17/6/2026 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | |
| Modificada | Media (5.9) | 2.6% | — | Fedoraproject FedoraOpensuseLibssh2Debian Linux | 13/4/2016 | 17/6/2026 | The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug." | |
| Modificada | Media (6.8) | 3.5% | — | Debian LinuxLibssh2Fedoraproject Fedora | 13/3/2015 | 17/6/2026 | The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet. | |
| Modificada | Alta (7.5) | 2.5% | — | Georgia Softworks Ssh2 Server | 8/1/2008 | 16/6/2026 | Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message. | |
| Modificada | Alta (7.5) | 9.2% | — | Georgia Softworks Ssh2 Server | 8/1/2008 | 16/6/2026 | Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password. | |
| Modificada | Alta (7.2) | 0.89% | — | SSHSsh2 | 31/12/2002 | 16/6/2026 | SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access. | |
| Modificada | Alta (10) | 7.9% | — | Ssh2 | 25/11/2002 | 16/6/2026 | Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Alta (7.2) | 0.45% | — | Ssh2 | 25/11/2002 | 16/6/2026 | SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges. | |
| Modificada | Media (5) | 1.6% | — | Ssh2 | 27/6/2001 | 16/6/2026 | SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections. | |
| Modificada | Media (5.1) | 0.97% | — | Openbsd OpensshSSHSsh2 | 24/2/2000 | 16/6/2026 | The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program. | |
| Modificada | Media (5) | 1.5% | — | Ssh2 | 9/6/1999 | 16/6/2026 | ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server. | |
| Modificada | Alta (7.5) | 1.6% | — | Ssh2 | 13/5/1999 | 16/6/2026 | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs. | |
| Modificada | Media (4.6) | 0.39% | — | SSHSsh2 | 1/1/1999 | 16/6/2026 | In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. | |
| Modificada | Media (4.6) | 0.34% | — | Ssh2 | 29/12/1998 | 16/6/2026 | SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root. |