Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

github логотип

GHSA-jrwv-mv4h-7rrq

больше 1 года назад

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2025-26465

больше 1 года назад

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2025-26465

больше 1 года назад

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-26465

больше 1 года назад

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2025-26465

больше 1 года назад

Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2025-26465

больше 1 года назад

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option ...

CVSS3: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0744-1

больше 1 года назад

Security update for openssh8.4

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0659-1

больше 1 года назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0605-1

больше 1 года назад

Security update for openssh

EPSS: Низкий
rocky логотип

RLSA-2025:6993

10 месяцев назад

Moderate: openssh security update

EPSS: Низкий
rocky логотип

RLSA-2025:16823

10 месяцев назад

Moderate: openssh security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-6993

около 1 года назад

ELSA-2025-6993: openssh security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-16823

10 месяцев назад

ELSA-2025-16823: openssh security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-01959

больше 1 года назад

Уязвимость компонента VerifyHostKeyDNS средства криптографической защиты OpenSSH, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0585-1

больше 1 года назад

Security update for openssh

EPSS: Низкий
redos логотип

ROS-20250307-13

больше 1 года назад

Уязвимость openssh

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jrwv-mv4h-7rrq

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
7%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-26465

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
7%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-26465

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
7%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-26465

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

CVSS3: 6.8
7%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-26465

Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled

CVSS3: 6.8
7%
Низкий
больше 1 года назад
debian логотип
CVE-2025-26465

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option ...

CVSS3: 6.8
7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0744-1

Security update for openssh8.4

7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0659-1

Security update for openssh

7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0605-1

Security update for openssh

7%
Низкий
больше 1 года назад
rocky логотип
RLSA-2025:6993

Moderate: openssh security update

7%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:16823

Moderate: openssh security update

7%
Низкий
10 месяцев назад
oracle-oval логотип
ELSA-2025-6993

ELSA-2025-6993: openssh security update (MODERATE)

7%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-16823

ELSA-2025-16823: openssh security update (MODERATE)

7%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-01959

Уязвимость компонента VerifyHostKeyDNS средства криптографической защиты OpenSSH, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.8
7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0585-1

Security update for openssh

больше 1 года назад
redos логотип
ROS-20250307-13

Уязвимость openssh

CVSS3: 6.8
7%
Низкий
больше 1 года назад

Уязвимостей на страницу