Search: "ssh"

1264 CVEs found

ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges via unspecified vectors.

Published: 2008-01-09
Products: 6
Vendors:
ssh linux opengroup

Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.

Published: 2008-02-05
Products: 1
Vendors:
progress
CVE-2008-0852
5.0 MEDIUM

freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.

Published: 2008-02-21
Products: 1
Vendors:
freesshd
CVE-2008-1483
6.9 MEDIUM

OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as...

Published: 2008-03-24
Products: 1
Vendors:
openbsd
CVE-2008-1537
6.8 MEDIUM

Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page pa...

Published: 2008-03-28
Products: 1
Vendors:
powerscripts
CVE-2008-0704
10.0 HIGH

Unspecified vulnerability in the SSH server in HP OpenVMS TCP/IP Services on OpenVMS on the Alpha platform with 5.4 before ECO 7, and on the Integrity and Alpha platforms with 5.5 before ECO 3 and 5.6...

Published: 2008-03-28
Products: 6
Vendors:
hp
CVE-2008-1657
6.5 MEDIUM

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

Published: 2008-04-02
Products: 6
Vendors:
openbsd
CVE-2008-2285
5.0 MEDIUM

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by gues...

Published: 2008-05-18
Products: 3
Vendors:
ubuntu

The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon out...

Published: 2008-05-22
Products: 2
Vendors:
icon-labs cisco

Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service ...

Published: 2008-05-22
Products: 2
Vendors:
icon-labs cisco

Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers ...

Published: 2008-05-22
Products: 3
Vendors:
icon-labs cisco

Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk6...

Published: 2008-05-22
Products: 4
Vendors:
cisco

Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) command.

Published: 2008-06-06
Products: 1
Vendors:
freesshd

Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE...

Published: 2008-06-27
Products: 1
Vendors:
hedgehog-cms
CVE-2008-3234
6.5 MEDIUM

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, follow...

Published: 2008-07-18
Products: 2
Vendors:
debian openbsd
CVE-2008-3385
6.8 MEDIUM

Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content...

Published: 2008-07-30
Products: 2
Vendors:
linuxwebshop

Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p, (2) cat, and (3) archive...

Published: 2008-08-10
Products: 1
Vendors:
dayfox_designs
CVE-2008-3731
4.0 MEDIUM

Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP c...

Published: 2008-08-20
Products: 8
Vendors:
solarwinds
CVE-2008-4181
6.8 MEDIUM

Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated ...

Published: 2008-09-23
Products: 133
Vendors:
netenberg
CVE-2008-3825
4.4 MEDIUM

pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local use...

Published: 2008-10-03
Products: 2
Vendors:
redhat