Search CVE reports


Toggle filters

41 – 50 of 50 results


CVE-2015-3146

Low priority

Some fixes available 3 of 5

The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2015-1782

Medium priority

Some fixes available 1 of 4

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

1 affected package

libssh2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh2 Not affected
Show less packages

CVE-2014-8132

Medium priority

Some fixes available 3 of 4

Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2014-0017

Medium priority

Some fixes available 3 of 4

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2013-0176

Medium priority

Some fixes available 4 of 5

The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2012-6063

Medium priority
Ignored

Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2012-4562

Medium priority

Some fixes available 4 of 5

Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly execute arbitrary code via unspecified vectors, which triggers a buffer overflow, infinite...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2012-4561

Low priority

Some fixes available 4 of 5

The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys.c in libssh before 0.5.3 free "an invalid pointer on an error path," which might allow...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2012-4560

Medium priority

Some fixes available 3 of 4

Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors.

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages

CVE-2012-4559

Low priority

Some fixes available 4 of 5

Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_userauth_pubkey function in auth.c, (4) sftp_parse_attr_3 function in sftp.c, and (5)...

1 affected package

libssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libssh
Show less packages