Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libssh2 HIGH 8.8
CVE-2026-66032

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio…

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66033

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in…

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66034

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbit…

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66035

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server …

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-58050

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attr…

Fix: after 1.11.1
Fix from $1,950 2026-06-28
Libssh2 MEDIUM 6.5
CVE-2026-58051

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse …

Fix: after 1.11.1
Fix from $1,600 2026-06-28
Libssh2 MEDIUM 6.5
CVE-2025-15661

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that …

Fix: after 1.11.1
Fix from $1,600 2026-06-18
Libssh2 HIGH 8.3
CVE-2026-55200

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bo…

Fix: after 1.11.1
Fix from $1,950 2026-06-17
Libssh2 HIGH 7.5
CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src…

Fix: after 1.11.1
Fix from $1,950 2026-06-17
Libssh2 HIGH 7.3
CVE-2026-7598

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c…

Fix: after 1.11.1
Fix from $1,950 2026-05-01
Libssh2 HIGH 7.5
CVE-2020-22218

An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

Patch available
Fix from $1,950 2023-08-22