Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2019-3858
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
0
Attacker Value
Unknown
CVE-2019-3862
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
0
Attacker Value
Unknown
CVE-2019-3859
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
0
Attacker Value
Unknown
CVE-2016-0787
Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
0
Attacker Value
Unknown
CVE-2015-1782
Disclosure Date: March 13, 2015 (last updated October 05, 2023)
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
0