VYPR

Libssh

by Libssh

Source repositories

CVEs (48)

  • CVE-2012-4560Nov 30, 2012
    risk 0.01cvss epss 0.06

    Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors.

  • CVE-2026-3731MedMar 8, 2026
    risk 0.00cvss 5.3epss 0.01

    A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to…

  • CVE-2014-8132Dec 29, 2014
    risk 0.00cvss epss 0.05

    Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.

  • CVE-2014-0017Mar 14, 2014
    risk 0.00cvss epss 0.00

    The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information…

  • CVE-2013-0176Feb 5, 2013
    risk 0.00cvss epss 0.03

    The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.

  • CVE-2012-6063Nov 30, 2012
    risk 0.00cvss epss 0.04

    Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector than CVE-2012-4559.

  • CVE-2012-4561Nov 30, 2012
    risk 0.00cvss epss 0.05

    The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys.c in libssh before 0.5.3 free "an invalid pointer on an error path," which might allow remote attackers to cause a denial of service…

  • CVE-2012-4559Nov 30, 2012
    risk 0.00cvss epss 0.05

    Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_userauth_pubkey function in auth.c, (4) sftp_parse_attr_3 function in sftp.c, and (5) try_publickey_from_file function in keyfiles.c in libssh…

Page 3 of 3