Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Privx CRITICAL 9.1
CVE-2024-30170

PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and i…

Fix: 31.3 / 32.3+
Fix from $2,300 2024-08-06
Tectia Client HIGH 8.8
CVE-2021-27891

SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.

Fix: 6.4.19+
Fix from $1,950 2021-03-15
Tectia Client HIGH 7.8
CVE-2021-27892

SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected.

Fix: 6.4.19+
Fix from $1,950 2021-03-15
Tectia Client HIGH 7.0
CVE-2021-27893

SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affecte…

Fix: 6.4.19+
Fix from $1,950 2021-03-15
Tectia Server HIGH 9.3
CVE-2012-5975EPSS 36%

The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2…

No fix yet
Fix from $1,950 2012-12-04
Tectia Client HIGH 7.2
CVE-2007-5616

ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges via unsp…

Fix: 5.2.4 / 5.3.6+
Fix from $1,950 2008-01-09
Tectia Client MEDIUM 5.0
CVE-2006-5484

SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes P…

Fix: after 5.1.0
Fix from $1,600 2006-10-24
Tectia Client HIGH 7.2
CVE-2006-4315

Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server befor…

Patch available
Fix from $1,950 2006-08-23
Tectia Manager HIGH 7.2
CVE-2006-4316

SSH Tectia Management Agent 2.1.2 allows local users to gain root privileges by running a program called sshd, which is obtained from a process listi…

Patch available
Fix from $1,950 2006-08-23
Tectia Server HIGH 7.5
CVE-2005-4310

SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.

Patch available
Fix from $1,950 2005-12-17
Secure Shell MEDIUM 5.0
CVE-2003-1119

SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.

Patch available
Fix from $1,600 2003-12-31
Secure Shell For Servers HIGH 7.5
CVE-2002-1646

SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authenti…

Patch available
Fix from $1,950 2002-12-31
Ssh HIGH 7.2
CVE-2002-1715

SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-w…

No fix yet
Fix from $1,950 2002-12-31
Ssh2 HIGH 10.0
CVE-2002-1645EPSS 8%

Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary cod…

Patch available
Fix from $1,950 2002-11-25
Ssh2 HIGH 7.2
CVE-2002-1644

SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove t…

Patch available
Fix from $1,950 2002-11-25
Secure Shell HIGH 7.2
CVE-2001-0553

SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access…

Patch available
Fix from $1,950 2001-08-14
Ssh HIGH 7.5
CVE-2001-0471EPSS 6%

SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise …

Fix: after 1.2.30
Fix from $1,950 2001-06-27
Ssh2 MEDIUM 5.0
CVE-2001-0364

SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.

Mitigation only
Fix from $1,600 2001-06-27
Ssh HIGH 7.5
CVE-2001-1473EPSS 6%

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a…

Mitigation only
Fix from $1,950 2001-01-18
Ssh HIGH 7.5
CVE-2001-1475

SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.

Patch available
Fix from $1,950 2001-01-18
Ssh HIGH 7.5
CVE-2001-1476

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user …

Patch available
Fix from $1,950 2001-01-18
Ssh MEDIUM 5.0
CVE-2001-1469

The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy…

No fix yet
Fix from $1,600 2001-01-18
Ssh MEDIUM 5.0
CVE-2001-1470

The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify th…

Mitigation only
Fix from $1,600 2001-01-18
Ssh MEDIUM 5.0
CVE-2001-1474

SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the loc…

Mitigation only
Fix from $1,600 2001-01-18
Ssh HIGH 7.2
CVE-2000-0575

SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is loggin…

Patch available
Fix from $1,950 2000-07-05
Ssh2 MEDIUM 5.0
CVE-1999-1231

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid…

Patch available
Fix from $1,600 1999-06-09
Ssh2 HIGH 7.5
CVE-1999-1029

SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a r…

Patch available
Fix from $1,950 1999-05-13
Ssh HIGH 10.0
CVE-1999-0248

A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.

Mitigation only
Fix from $1,950 1999-01-01
Ssh HIGH 7.5
CVE-1999-0310

SSH 1.2.25 on HP-UX allows access to new user accounts.

No fix yet
Fix from $1,950 1998-09-01
Secure Shell MEDIUM 5.0
CVE-1999-1085

SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers t…

Mitigation only
Fix from $1,600 1998-06-12