Vulnerabilities > Openbsd > Openssh > 3.0

DATE CVE VULNERABILITY TITLE RISK
2003-09-22 CVE-2003-0693 Unspecified vulnerability in Openbsd Openssh
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.
network
low complexity
openbsd
critical
10.0
2002-07-03 CVE-2002-0640 Buffer Overflow vulnerability in OpenSSH Challenge-Response
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).
network
low complexity
openbsd
critical
10.0
2002-07-03 CVE-2002-0639 Integer Overflow or Wraparound vulnerability in Openbsd Openssh
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
network
low complexity
openbsd CWE-190
critical
9.8
2002-06-18 CVE-2002-0575 Buffer Overflow vulnerability in OpenSSH Kerberos 4 TGT/AFS Token
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges.
network
low complexity
openbsd
7.5
2002-03-15 CVE-2002-0083 Off-by-one Error vulnerability in multiple products
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
9.8
2001-12-31 CVE-2001-1507 Unspecified vulnerability in Openbsd Openssh 3.0/3.0P1
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
network
low complexity
openbsd
7.5
2001-12-21 CVE-2001-0872 OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
local
low complexity
openbsd redhat suse
7.2