Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)6.4%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+121/3/201917/6/2026
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
ModificadaAlta (8.8)9.3%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1021/3/201917/6/2026
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
ModificadaCrítica (9.1)7.9%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+121/3/201917/6/2026
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
ModificadaCrítica (9.1)6.3%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+121/3/201917/6/2026
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
ModificadaMedia (5.9)2.6%—Fedoraproject FedoraOpensuseLibssh2Debian Linux13/4/201617/6/2026
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
ModificadaMedia (6.8)3.5%—Debian LinuxLibssh2Fedoraproject Fedora13/3/201517/6/2026
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
ModificadaAlta (7.5)2.5%—Georgia Softworks Ssh2 Server8/1/200816/6/2026
Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.
ModificadaAlta (7.5)9.2%—Georgia Softworks Ssh2 Server8/1/200816/6/2026
Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.
ModificadaAlta (7.2)0.89%—SSHSsh231/12/200216/6/2026
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.
ModificadaAlta (10)7.9%—Ssh225/11/200216/6/2026
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.
ModificadaAlta (7.2)0.45%—Ssh225/11/200216/6/2026
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.
ModificadaMedia (5)1.6%—Ssh227/6/200116/6/2026
SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.
ModificadaMedia (5.1)0.97%—Openbsd OpensshSSHSsh224/2/200016/6/2026
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
ModificadaMedia (5)1.5%—Ssh29/6/199916/6/2026
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.
ModificadaAlta (7.5)1.6%—Ssh213/5/199916/6/2026
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
ModificadaMedia (4.6)0.39%—SSHSsh21/1/199916/6/2026
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
ModificadaMedia (4.6)0.34%—Ssh229/12/199816/6/2026
SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.