Количество 16
Количество 16
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
CVE-2026-58050
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
CVE-2026-58050
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...
GHSA-mf77-5hj2-98w9
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
BDU:2026-08915
Уязвимость функции publickey_response_success() библиотеки libssh2, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
ROS-20260907-80-0031
Уязвимость nmap
ROS-20260907-73-0030
Уязвимость nmap
ROS-20260810-80-0021
Уязвимость libssh2
ROS-20260810-73-0034
Уязвимость libssh2
openSUSE-SU-2026:21549-1
Security update for libssh2_org
SUSE-SU-2026:4095-1
Security update for libssh2_org
SUSE-SU-2026:3541-1
Security update for libssh2_org
SUSE-SU-2026:3526-1
Security update for libssh2_org
SUSE-SU-2026:3525-1
Security update for libssh2_org
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation | 0% Низкий | 3 месяца назад | ||
CVE-2026-58050 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ... | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
GHSA-mf77-5hj2-98w9 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
BDU:2026-08915 Уязвимость функции publickey_response_success() библиотеки libssh2, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код | CVSS3: 7 | 0% Низкий | 3 месяца назад | |
ROS-20260907-80-0031 Уязвимость nmap | CVSS3: 7 | 0% Низкий | 13 дней назад | |
ROS-20260907-73-0030 Уязвимость nmap | CVSS3: 7 | 0% Низкий | 13 дней назад | |
ROS-20260810-80-0021 Уязвимость libssh2 | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
ROS-20260810-73-0034 Уязвимость libssh2 | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
openSUSE-SU-2026:21549-1 Security update for libssh2_org | около 1 месяца назад | |||
SUSE-SU-2026:4095-1 Security update for libssh2_org | 10 дней назад | |||
SUSE-SU-2026:3541-1 Security update for libssh2_org | около 1 месяца назад | |||
SUSE-SU-2026:3526-1 Security update for libssh2_org | около 1 месяца назад | |||
SUSE-SU-2026:3525-1 Security update for libssh2_org | около 1 месяца назад |
Уязвимостей на страницу