Show filters
309 Total Results
Displaying 121-130 of 309
Sort by:
Attacker Value
Unknown
CVE-2018-1999036
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.
0
Attacker Value
Unknown
CVE-2017-2648
Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
0
Attacker Value
Unknown
CVE-2018-14441
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
0
Attacker Value
Unknown
CVE-2018-14440
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
0
Attacker Value
Unknown
CVE-2018-9853
Disclosure Date: July 10, 2018 (last updated November 08, 2023)
Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to login to an unprivileged account on the server.
0
Attacker Value
Unknown
CVE-2018-1000601
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
0
Attacker Value
Unknown
CVE-2018-3737
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
0
Attacker Value
Unknown
CVE-2018-7749
Disclosure Date: March 12, 2018 (last updated November 08, 2023)
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
0
Attacker Value
Unknown
CVE-2017-1000475
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.
0
Attacker Value
Unknown
CVE-2016-10708
Disclosure Date: January 21, 2018 (last updated November 08, 2023)
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
0