Show filters
106 Total Results
Displaying 71-80 of 106
Sort by:
Attacker Value
Unknown
CVE-2003-1119
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.
0
Attacker Value
Unknown
CVE-2003-1120
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.
0
Attacker Value
Unknown
CVE-2002-1646
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.
0
Attacker Value
Unknown
CVE-2002-1715
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.
0
Attacker Value
Unknown
CVE-2002-1358
Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown
CVE-2002-1360
Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown
CVE-2002-1359
Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown
CVE-2002-1357
Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
0
Attacker Value
Unknown
CVE-2002-1645
Disclosure Date: November 25, 2002 (last updated February 22, 2025)
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.
0
Attacker Value
Unknown
CVE-2002-1644
Disclosure Date: November 25, 2002 (last updated February 22, 2025)
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.
0