Количество 11
Количество 11
BDU:2022-01880
Уязвимость средства криптографической защиты OpenSSH, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
ROS-20250505-12
Уязвимость openssh
ALT-PU-2023-4460
ALT-PU-2023-4460: package `openssh` update to version 9.3p1-alt1
ALT-PU-2024-7269
ALT-PU-2024-7269: package `openssh-gostcrypto` update to version 9.6p1-alt1.gost
CVE-2016-20012
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
CVE-2016-20012
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
CVE-2016-20012
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
CVE-2016-20012
OpenSSH through 8.7 allows remote attackers who have a suspicion that a certain combination of username and public key is known to an SSH server to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
CVE-2016-20012
OpenSSH through 8.7 allows remote attackers, who have a suspicion that ...
GHSA-84j4-ccmw-hwpg
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session.
ALT-PU-2024-9513
ALT-PU-2024-9513: package `openssh-gostcrypto` update to version 9.6p1-alt2.gost
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2022-01880 Уязвимость средства криптографической защиты OpenSSH, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 5.3 | 5% Низкий | больше 24 лет назад | |
ROS-20250505-12 Уязвимость openssh | CVSS3: 5.3 | 5% Низкий | больше 1 года назад | |
ALT-PU-2023-4460 ALT-PU-2023-4460: package `openssh` update to version 9.3p1-alt1 | CVSS3: 7.8 | около 3 лет назад | ||
ALT-PU-2024-7269 ALT-PU-2024-7269: package `openssh-gostcrypto` update to version 9.6p1-alt1.gost | CVSS3: 9.8 | больше 2 лет назад | ||
CVE-2016-20012 OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product | CVSS3: 5.3 | 5% Низкий | около 5 лет назад | |
CVE-2016-20012 OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product | CVSS3: 5.9 | 5% Низкий | больше 10 лет назад | |
CVE-2016-20012 OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product | CVSS3: 5.3 | 5% Низкий | около 5 лет назад | |
CVE-2016-20012 OpenSSH through 8.7 allows remote attackers who have a suspicion that a certain combination of username and public key is known to an SSH server to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product | CVSS3: 5.3 | 5% Низкий | почти 5 лет назад | |
CVE-2016-20012 OpenSSH through 8.7 allows remote attackers, who have a suspicion that ... | CVSS3: 5.3 | 5% Низкий | около 5 лет назад | |
GHSA-84j4-ccmw-hwpg OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. | CVSS3: 5.3 | 5% Низкий | больше 4 лет назад | |
ALT-PU-2024-9513 ALT-PU-2024-9513: package `openssh-gostcrypto` update to version 9.6p1-alt2.gost | CVSS3: 9.8 | около 2 лет назад |
Уязвимостей на страницу