Search: "ssh"

1265 CVEs found

Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pathname in the configfile parameter to (1) update08...

Published: 2009-12-22
Products: 1
Vendors:
php-calendar

Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consump...

Published: 2010-01-21
Products: 9
Vendors:
cisco

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy r...

Published: 2010-03-25
Products: 2
Vendors:
mozilla

Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a craf...

Published: 2010-03-30
Products: 26
Vendors:
apple

The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier for remote attackers to conduct man-in-the-middle attacks and spoof arbitrary s...

Published: 2010-04-13
Products: 12
Vendors:
vsecurity
CVE-2009-4845
5.0 MEDIUM

The configuration page in ToutVirtual VirtualIQ Pro 3.2 build 7882 contains cleartext SSH credentials, which allows remote attackers to obtain sensitive information by reading the username and passwor...

Published: 2010-05-07
Products: 1
Vendors:
toutvirtual

Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegStri...

Published: 2010-06-16
Products: 1
Vendors:
symantec

Unspecified vulnerability on the Cisco Firewall Services Module (FWSM) with software 3.2 before 3.2(17.2), 4.0 before 4.0(11.1), and 4.1 before 4.1(1.2) for Catalyst 6500 series switches and 7600 seri...

Published: 2010-08-09
Products: 18
Vendors:
cisco

Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow ...

Published: 2010-08-10
Products: 2
Vendors:
cisco
CVE-2010-3038
10.0 HIGH

Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier fo...

Published: 2010-11-22
Products: 5
Vendors:
linux cisco
CVE-2011-0539
5.0 MEDIUM

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which mig...

Published: 2011-02-10
Products: 2
Vendors:
openbsd
CVE-2010-4755
4.0 MEDIUM

The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow ...

Published: 2011-03-02
Products: 84
Vendors:
netbsd freebsd openbsd
CVE-2011-0437
4.0 MEDIUM

shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) before 0.32.9 allows remote authenticated users to delete arbitrary accounts via the edssh_acco...

Published: 2011-03-07
Products: 35
Vendors:
gplhost
CVE-2011-1137
5.0 MEDIUM

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH messa...

Published: 2011-03-11
Products: 65
Vendors:
proftpd
CVE-2011-0189
5.0 MEDIUM

The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attacke...

Published: 2011-03-23
Products: 16
Vendors:
apple

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which...

Published: 2011-05-31
Products: 12
Vendors:
ssh erlang

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by mak...

Published: 2011-05-31
Products: 8
Vendors:
cisco
CVE-2011-1623
10.0 HIGH

Cisco Media Processing Software before 1.2 on Media Experience Engine (MXE) 5600 devices has a default root password, which makes it easier for context-dependent attackers to obtain access via (1) the...

Published: 2011-06-02
Products: 6
Vendors:
cisco

Unspecified vulnerability in the Solaris component in Oracle Sun Products Suite 9 and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to SSH.

Published: 2011-07-20
Products: 2
Vendors:
oracle
CVE-2011-2294
5.0 MEDIUM

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to SSH.

Published: 2011-07-21
Products: 2
Vendors:
sun