VYPR

Libssh2

by Libssh2

Source repositories

CVEs (25)

  • CVE-2019-3861MedMar 25, 2019
    risk 0.33cvss 5.0epss 0.05

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client…

  • CVE-2019-3860MedMar 25, 2019
    risk 0.33cvss 5.0epss 0.05

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

  • CVE-2019-3858MedMar 21, 2019
    risk 0.33cvss 5.0epss 0.06

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

  • CVE-2026-55199MedJun 17, 2026
    risk 0.31cvss 5.9epss 0.01

    libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A…

  • CVE-2015-1782Mar 13, 2015
    risk 0.00cvss —epss 0.04

    The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

Page 2 of 2