Ssh Ssh2 vulnerabilities

10 known vulnerabilities affecting ssh/ssh2.

Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2020-26301HIGH≥ 0, < 1.4.02021-09-21
CVE-2020-26301 [HIGH] CWE-78 OS Command Injection in ssh2 OS Command Injection in ssh2 ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.
ghsaosv
CVE-2002-1715HIGHCVSS 7.2PoCv2.0v2.0.1+18 more2002-12-31
CVE-2002-1715 [HIGH] CVE-2002-1715: SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.
nvd
CVE-2002-1645CRITICALCVSS 10.0v3.1v3.1.1+4 more2002-11-25
CVE-2002-1645 [CRITICAL] CVE-2002-1645: Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.
nvd
CVE-2002-1644HIGHCVSS 7.2v2.0.13v2.1+13 more2002-11-25
CVE-2002-1644 [HIGH] CVE-2002-1644: SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when runnin SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.
nvd
CVE-2001-0364MEDIUMCVSS 5.0v2.42001-06-27
CVE-2001-0364 [MEDIUM] CVE-2001-0364: SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of servi SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.
nvd
CVE-2000-0217MEDIUMCVSS 5.1v2.0v2.0.1+11 more2000-02-24
CVE-2000-0217 [MEDIUM] CVE-2000-0217: The default configuration of SSH allows X forwarding, which could allow a remote attacker to control The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
nvd
CVE-1999-1231MEDIUMCVSS 5.0v2.0v2.0.1+11 more1999-06-09
CVE-1999-1231 [MEDIUM] CVE-1999-1231: ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct pas ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.
nvd
CVE-1999-1029HIGHCVSS 7.5v2.0v2.0.1+10 more1999-05-13
CVE-1999-1029 [HIGH] CVE-1999-1029: SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
nvd
CVE-1999-0398MEDIUMCVSS 4.6v2.0.111999-01-01
CVE-1999-0398 [MEDIUM] CVE-1999-0398: In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accou In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
nvd
CVE-1999-1159MEDIUMCVSS 4.6v2.0.111998-12-29
CVE-1999-1159 [MEDIUM] CVE-1999-1159: SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
nvd
Ssh Ssh2 vulnerabilities | cvebase