VYPR

OpenSSH

by OpenSSH

Source repositories

CVEs (65)

  • CVE-2008-1657Apr 2, 2008
    risk 0.00cvss epss 0.02

    OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

  • CVE-2008-1483Mar 24, 2008
    risk 0.00cvss epss 0.00

    OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by…

  • CVE-2007-3102Oct 18, 2007
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from…

  • CVE-2007-4752Sep 12, 2007
    risk 0.00cvss epss 0.02

    ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

  • CVE-2007-4654Sep 4, 2007
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets…

Page 4 of 4