Page 15 of 88 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 16EXPL: 2

Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges. • https://www.exploit-db.com/exploits/21402 ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-022.2.txt http://archives.neohapsis.com/archives/bugtraq/2002-04/0298.html http://archives.neohapsis.com/archives/bugtraq/2002-04/0394.html http://marc.info/?l=bugtraq&m=102167972421837&w=2 http://marc.info/?l=vuln-dev&m=101924296115863&w=2 http://online.securityfocus.com/archive/1/268718 http://online.securityfocus.com/archive/1/269701 http://www.iss.net/security_center& •

CVSS: 10.0EPSS: 1%CPEs: 38EXPL: 1

Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. Error 'off-by-one' en el código de canal de OpenSSH 2.0 a 3.0.2 permite a usuarios locales o a servidores remotos ganar privilegios. • https://www.exploit-db.com/exploits/21314 ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:13.openssh.asc ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-004.txt.asc ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.10/CSSA-2002-SCO.10.txt ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.11/CSSA-2002-SCO.11.txt http://archives.neohapsis.com/archives/bugtraq/2002-03/0108.html http://archives.neohapsis.com/archives/vulnw • CWE-193: Off-by-one Error •

CVSS: 7.5EPSS: 2%CPEs: 2EXPL: 0

OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged. • http://msgs.securepoint.com/cgi-bin/get/bugtraq0111/114.html http://www.iss.net/security_center/static/7598.php http://www.openbsd.org/errata30.html#sshd http://www.securityfocus.com/bid/3560 •

CVSS: 6.8EPSS: 1%CPEs: 1EXPL: 0

SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user's authorized_keys file. • http://archives.neohapsis.com/archives/bugtraq/2001-02/0159.html http://online.securityfocus.com/bid/2356 http://www.openbsd.org/advisories/ssh_bypass.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/6084 • CWE-287: Improper Authentication •

CVSS: 7.2EPSS: 0%CPEs: 9EXPL: 0

OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges. OpenSSH 3.0.1 y anteriores con UseLogin activado no limpia variables de entorno críticas como LD_PRELOAD, lo que permite a usuario locales ganar privilegios de root. • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-042.1.txt http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000446 http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:092 http://lists.suse.com/archives/suse-security-announce/2001-Dec/0001.html http://marc.info/?l=bugtraq&m=100749779131514&w=2 http://marc.info/?l=openssh-unix-dev&m=100747128105913&w=2 http://www.ciac.org/ciac/bulletins/m-026.shtml http://www.debian.org/security/2001/dsa- •