Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dropbear Ssh HIGH 8.1
CVE-2020-36254

scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

Fix: 2020.79+
Fix from $1,950 2021-02-25
Dropbear Ssh MEDIUM 5.3
CVE-2019-12953

Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.

Fix: after 2018.76
Fix from $1,600 2020-12-30
Dropbear Ssh HIGH 7.5
CVE-2017-2659

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, th…

Fix: 2013.59+
Fix from $1,950 2019-03-21
Dropbear Ssh CRITICAL 9.8
CVE-2016-7406EPSS 10%

Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) …

Fix: after 2016.73
Fix from $2,300 2017-03-03
Dropbear Ssh CRITICAL 9.8
CVE-2016-7407EPSS 6%

The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.

Fix: after 2016.73
Fix from $2,300 2017-03-03
Dropbear Ssh HIGH 8.8
CVE-2016-7408

The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.

Fix: after 2016.73
Fix from $1,950 2017-03-03
Dropbear Ssh MEDIUM 5.5
CVE-2016-7409

The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument…

Fix: after 2016.73
Fix from $1,600 2017-03-03
Dropbear Ssh MEDIUM 6.4
CVE-2016-3116EPSS 19%

CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via craft…

Fix: after 2015.71
Fix from $1,600 2016-03-22
Dropbear Ssh MEDIUM 5.0
CVE-2013-4421EPSS 6%

The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumptio…

Fix: 2013.59+
Fix from $1,600 2013-10-25
Dropbear Ssh MEDIUM 5.0
CVE-2013-4434EPSS 6%

Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user accou…

Fix: 2013.59+
Fix from $1,600 2013-10-25
Dropbear Ssh HIGH 7.5
CVE-2007-1099

dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attacker…

Fix: 0.49+
Fix from $1,950 2007-02-26
Dropbear Ssh MEDIUM 5.0
CVE-2006-1206EPSS 12%

Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attacke…

Fix: after 0.47
Fix from $1,600 2006-03-14
Dropbear Ssh HIGH 7.5
CVE-2004-2486

The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

Fix: 0.43+
Fix from $1,950 2004-12-31