Search: "ssh"

1263 CVEs found

CVE-2002-1547
5.0 MEDIUM

Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated v...

Published: 2003-03-31
Products: 1
Vendors:
juniper
CVE-2002-1520
10.0 HIGH

The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows r...

Published: 2003-04-02
Products: 9
Vendors:
rapidstream watchguard
CVE-2003-0259
5.0 MEDIUM

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.

Published: 2003-05-27
Products: 36
Vendors:
cisco

ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.

Published: 2003-10-20
Products: 7
Vendors:
compaq
CVE-2003-0786
10.0 HIGH

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote atta...

Published: 2003-11-17
Products: 2
Vendors:
openbsd
CVE-2003-1119
5.0 MEDIUM

SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.

Published: 2003-12-31
Products: 2
Vendors:
ssh

Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.

Published: 2003-12-31
Products: 2
Vendors:
ssh

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, w...

Published: 2003-12-31
Products: 45
Vendors:
openbsd
CVE-2004-1357
5.0 MEDIUM

The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide t...

Published: 2004-04-07
Products: 2
Vendors:
sun
CVE-2004-2004
10.0 HIGH

The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.

Published: 2004-05-06
Products: 1
Vendors:
suse

The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attacke...

Published: 2004-07-07
Products: 1
Vendors:
kde

Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port fo...

Published: 2004-07-07
Products: 1
Vendors:
apple
CVE-2004-0551
5.0 MEDIUM

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid ...

Published: 2004-08-06
Products: 294
Vendors:
cisco

Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.

Published: 2004-08-18
Products: 8
Vendors:
apple

Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mo...

Published: 2004-12-31
Products: 8
Vendors:
putty
CVE-2004-1446
5.0 MEDIUM

Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.

Published: 2004-12-31
Products: 106
Vendors:
juniper
CVE-2004-2069
5.0 MEDIUM

sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceedi...

Published: 2004-12-31
Products: 2
Vendors:
openbsd

The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

Published: 2004-12-31
Products: 1
Vendors:
dropbear_ssh_project
CVE-2004-2760
6.8 MEDIUM

sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt wit...

Published: 2004-12-31
Products: 2
Vendors:
openbsd
CVE-2004-1008
10.0 HIGH

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads ...

Published: 2005-01-10
Products: 10
Vendors:
tortoisecvs putty