cbcvebase.

Openbsd OpenSSH vulnerabilities

136 known vulnerabilities affecting openbsd/openssh.

Total CVEs
136
CISA KEV
0
Public exploits
24
Exploited in wild
10
Severity breakdown
CRITICAL13HIGH48MEDIUM60LOW15

Vulnerabilities

Page 6 of 7
CVE-2001-1380P4HIGHCVSS 7.5≤ 2.9.92001-10-18
CVE-2001-1380 [HIGH] CVE-2001-1380: OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/author OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.
nvd
CVE-2002-0765P4HIGHCVSS 7.5v3.2.22002-08-12
CVE-2002-0765 [HIGH] CVE-2002-0765: sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
nvdosv
CVE-2026-73282P4MEDIUMCVSS 4.8fixed in 10.52026-08-11
CVE-2026-73282 [MEDIUM] CWE-416 CVE-2026-73282: In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remo In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
nvd
CVE-2006-0225P4MEDIUMCVSS 4.6v3.0v3.0.1+31 more2006-01-25
CVE-2006-0225 [MEDIUM] CVE-2006-0225: scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.
nvdosv
CVE-2006-0883P4MEDIUMCVSS 5.0v3.8.1p12006-03-07
CVE-2006-0883 [MEDIUM] CWE-399 CVE-2006-0883: OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.
nvdosv
CVE-2001-1382P4MEDIUMCVSS 5.0≤ 2.9.9p22001-09-27
CVE-2001-1382 [MEDIUM] CVE-2001-1382: The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used.
nvd
CVE-2023-51384P4MEDIUMCVSS 5.5≥ 8.9, < 9.62023-12-18
CVE-2023-51384 [MEDIUM] CWE-284 CVE-2023-51384: In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. Whe In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
nvdosv
CVE-2001-0872P4HIGHCVSS 7.2≤ 3.0.12001-12-21
CVE-2001-0872 [HIGH] CVE-2001-0872: OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment varia OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
nvd
CVE-2016-10011P4MEDIUMCVSS 6.2≤ 7.32017-01-05
CVE-2016-10011 [MEDIUM] CWE-320 CVE-2016-10011: authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
nvdosv
CVE-2009-2904P4MEDIUMCVSS 6.9v4.3v4.82009-10-01
CVE-2009-2904 [MEDIUM] CWE-16 CVE-2009-2904: A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in Ope A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.
nvd
CVE-2007-4654P4MEDIUMCVSS 5.0v3.0.2p12007-09-04
CVE-2007-4654 [MEDIUM] CVE-2007-4654: Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Con Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibl
nvd
CVE-2008-2285P4HIGHCVSS 7.5≥ 0, < 1:4.7p1-102008-05-18
CVE-2008-2285 [HIGH] CVE-2008-2285: The ssh-vulnkey tool on Ubuntu Linux 7 The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.
osv
CVE-2021-36368P4LOWCVSS 3.7fixed in 8.92022-03-13
CVE-2021-36368 [LOW] CWE-287 CVE-2021-36368: An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with a An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to
nvdosv
CVE-2007-3102P4MEDIUMCVSS 4.3v4.3p22007-10-18
CVE-2007-3102 [MEDIUM] CVE-2007-3102: Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedo Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from third party information.
nvd
CVE-2007-2243P4MEDIUMCVSS 5.0v1.2v1.2.1+60 more2007-04-25
CVE-2007-2243 [MEDIUM] CWE-287 CVE-2007-2243: OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.
nvd
CVE-2011-4327P4MEDIUMCVSS 5.5≤ 5.8v1.2+78 more2014-02-03
CVE-2011-4327 [MEDIUM] CWE-200 CVE-2011-4327: ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper w ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.
nvd
CVE-2004-0175P4MEDIUMCVSS 4.3v3.0v3.0.1+13 more2004-08-18
CVE-2004-0175 [MEDIUM] CVE-2004-0175: Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.
nvdosv
CVE-2010-4755P4MEDIUMCVSS 4.0≤ 5.8v1.2+78 more2011-03-02
CVE-2010-4755 [MEDIUM] CVE-2010-4755: The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5. The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrate
nvd
CVE-2004-2069P4MEDIUMCVSS 5.0v3.6.1p2v3.7.1p22004-12-31
CVE-2004-2069 [MEDIUM] CVE-2004-2069: sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).
nvdosv
CVE-2005-2798P4MEDIUMCVSS 5.0v3.0v3.0.1+30 more2005-09-06
CVE-2005-2798 [MEDIUM] CVE-2005-2798: sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.
nvdosv
Openbsd OpenSSH vulnerabilities | cvebase