Search: "ssh"

1264 CVEs found

CVE-2006-3631
5.0 MEDIUM

Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

Published: 2006-07-21
Products: 10
Vendors:
wireshark

Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running...

Published: 2006-08-23
Products: 50
Vendors:
ssh

SSH Tectia Management Agent 2.1.2 allows local users to gain root privileges by running a program called sshd, which is obtained from a process listing when the "Restart" action is selected from the M...

Published: 2006-08-23
Products: 5
Vendors:
ssh

sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not...

Published: 2006-09-27
Products: 56
Vendors:
openbsd
CVE-2006-4925
5.0 MEDIUM

packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be N...

Published: 2006-09-29
Products: 1
Vendors:
openbsd

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies ...

Published: 2006-10-10
Products: 2
Vendors:
novell openbsd
CVE-2006-5484
5.0 MEDIUM

SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allow...

Published: 2006-10-24
Products: 4
Vendors:
ssh

Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authe...

Published: 2006-11-08
Products: 1
Vendors:
openbsd
CVE-2006-6301
5.0 MEDIUM

DenyHosts 2.5 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to...

Published: 2006-12-06
Products: 1
Vendors:
denyhosts
CVE-2006-6302
5.0 MEDIUM

fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP...

Published: 2006-12-06
Products: 1
Vendors:
fail2ban

Unspecified vulnerability in SSH key based authentication in HP Integrated Lights Out (iLO) 1.70 through 1.87, and iLO 2 1.00 through 1.11, on Proliant servers, allows remote attackers to "gain unauth...

Published: 2006-12-18
Products: 4
Vendors:
hp
CVE-2007-0397
6.4 MEDIUM

The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public k...

Published: 2007-01-20
Products: 2
Vendors:
cisco
CVE-2007-1063
10.0 HIGH

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to ac...

Published: 2007-02-22
Products: 12
Vendors:
cisco

dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.

Published: 2007-02-26
Products: 1
Vendors:
dropbear_ssh_project
CVE-2007-0726
5.0 MEDIUM

The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished crea...

Published: 2007-03-13
Products: 20
Vendors:
apple

Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash...

Published: 2007-03-24
Products: 5
Vendors:
netsieben
CVE-2007-2063
4.4 MEDIUM

SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_...

Published: 2007-04-18
Products: 4
Vendors:
ssh
CVE-2007-2765
6.8 MEDIUM

blockhosts.py in BlockHosts before 2.0.3 does not properly parse daemon log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of servic...

Published: 2007-05-18
Products: 1
Vendors:
ac_zoom
CVE-2007-4321
6.8 MEDIUM

fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP a...

Published: 2007-08-14
Products: 1
Vendors:
fail2ban
CVE-2007-4322
6.8 MEDIUM

BlockHosts before 2.0.4 does not properly parse (1) sshd and (2) vsftpd log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of servic...

Published: 2007-08-14
Products: 1
Vendors:
ac_zoom