Search: "ssh"

1264 CVEs found

Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a long string to the (1) open (aka SSH_FXP_OPEN), (2) unlink, (3) ...

Published: 2008-10-24
Products: 1
Vendors:
goodtechsystems

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

Published: 2008-11-18
Products: 23
Vendors:
jscape

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4...

Published: 2008-11-19
Products: 167
Vendors:
ssh openbsd

Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some en...

Published: 2008-11-21
Products: 1
Vendors:
otmanager

Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to a...

Published: 2008-12-30
Products: 1
Vendors:
apertoblog

Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2....

Published: 2009-02-26
Products: 6
Vendors:
cisco
CVE-2009-1745
10.0 HIGH

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote ...

Published: 2009-05-21
Products: 2
Vendors:
armorlogic

Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE...

Published: 2009-06-30
Products: 1
Vendors:
awesomephp

Memory leak on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0, 5.1 before 5.1.163.0, and 5.0 and 5.2 before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 41...

Published: 2009-07-29
Products: 37
Vendors:
cisco

The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent at...

Published: 2009-07-30
Products: 1
Vendors:
fedorahosted
CVE-2008-7031
10.0 HIGH

Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH p...

Published: 2009-08-24
Products: 1
Vendors:
foxitsoftware
CVE-2008-7225
10.0 HIGH

Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH p...

Published: 2009-09-14
Products: 1
Vendors:
foxitsoftware

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users ...

Published: 2009-09-24
Products: 1
Vendors:
backuppc

Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via ...

Published: 2009-09-28
Products: 17
Vendors:
cisco
CVE-2009-2904
6.9 MEDIUM

A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges...

Published: 2009-10-01
Products: 6
Vendors:
redhat fedoraproject openbsd

Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter t...

Published: 2009-10-02
Products: 1
Vendors:
kneuro
CVE-2009-3710
10.0 HIGH

RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.

Published: 2009-10-16
Products: 2
Vendors:
riorey
CVE-2009-2818
5.0 MEDIUM

Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force ...

Published: 2009-11-10
Products: 59
Vendors:
apple
CVE-2009-2829
5.0 MEDIUM

Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving proc...

Published: 2009-11-10
Products: 1
Vendors:
apple
CVE-2009-4075
5.0 MEDIUM

Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon outage) via unknown v...

Published: 2009-11-25
Products: 52
Vendors:
sun