Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2023-48795
Disclosure Date: December 18, 2023 (last updated February 25, 2025)
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0…
2
Attacker Value
Unknown
CVE-2022-33035
Disclosure Date: June 29, 2022 (last updated February 24, 2025)
XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
0
Attacker Value
Unknown
CVE-2022-27966
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
0
Attacker Value
Unknown
CVE-2022-27965
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
0
Attacker Value
Unknown
CVE-2022-27964
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
0
Attacker Value
Unknown
CVE-2022-27963
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
0
Attacker Value
Unknown
CVE-2021-42095
Disclosure Date: October 07, 2021 (last updated November 28, 2024)
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.
0
Attacker Value
Unknown
CVE-2021-37326
Disclosure Date: August 15, 2021 (last updated February 23, 2025)
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
0
Attacker Value
Unknown
CVE-2019-17320
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.
0
Attacker Value
Unknown
CVE-2012-1009
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.
0