Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

github логотип

GHSA-gpcj-wh2f-rr23

почти 3 года назад

A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-f35j-mfvw-p857

больше 2 лет назад

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.

CVSS3: 3.9
EPSS: Низкий
fstec логотип

BDU:2024-00200

почти 3 года назад

Уязвимость библиотеки libssh, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-00199

почти 3 года назад

Уязвимость компонента ProxyCommand/ProxyJump библиотеки libssh, позволяющая нарушителю выполнить произвольный код

CVSS3: 3.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gpcj-wh2f-rr23

A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.

CVSS3: 3.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-f35j-mfvw-p857

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.

CVSS3: 3.9
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-00200

Уязвимость библиотеки libssh, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
1%
Низкий
почти 3 года назад
fstec логотип
BDU:2024-00199

Уязвимость компонента ProxyCommand/ProxyJump библиотеки libssh, позволяющая нарушителю выполнить произвольный код

CVSS3: 3.9
0%
Низкий
почти 3 года назад

Уязвимостей на страницу