Show filters
309 Total Results
Displaying 121-130 of 309
Sort by:
Attacker Value
Unknown

CVE-2018-1999036

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.
0
Attacker Value
Unknown

CVE-2017-2648

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
0
Attacker Value
Unknown

CVE-2018-14441

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
0
Attacker Value
Unknown

CVE-2018-14440

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
0
Attacker Value
Unknown

CVE-2018-9853

Disclosure Date: July 10, 2018 (last updated November 08, 2023)
Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to login to an unprivileged account on the server.
0
Attacker Value
Unknown

CVE-2018-1000601

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
0
Attacker Value
Unknown

CVE-2018-3737

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Attacker Value
Unknown

CVE-2018-7749

Disclosure Date: March 12, 2018 (last updated November 08, 2023)
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
0
Attacker Value
Unknown

CVE-2017-1000475

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.
0
Attacker Value
Unknown

CVE-2016-10708

Disclosure Date: January 21, 2018 (last updated November 08, 2023)
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
0