Show filters
106 Total Results
Displaying 71-80 of 106
Sort by:
Attacker Value
Unknown

CVE-2003-1119

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.
0
Attacker Value
Unknown

CVE-2003-1120

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.
0
Attacker Value
Unknown

CVE-2002-1646

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.
0
Attacker Value
Unknown

CVE-2002-1715

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.
0
Attacker Value
Unknown

CVE-2002-1358

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown

CVE-2002-1360

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown

CVE-2002-1359

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown

CVE-2002-1357

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown

CVE-2002-1645

Disclosure Date: November 25, 2002 (last updated February 22, 2025)
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.
0
Attacker Value
Unknown

CVE-2002-1644

Disclosure Date: November 25, 2002 (last updated February 22, 2025)
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.
0