Vulnerabilidades en The libssh2 Project

9 resultados
Análisis Vexday

O libssh2 Project apresenta 9 vulnerabilidades históricas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo no momento e nenhuma foi publicada recentemente, indicando risco estabilizado. A fraqueza predominante é CWE-125 (leitura fora dos limites), padrão em bibliotecas de baixo nível mal auditadas, exigindo atenção em integrações legacy mas sem urgência imediata.

CVE-2019-3855HIGHAn integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from EPSS 9.2%CVE-2019-3862HIGHAn out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message andEPSS 8.1%CVE-2019-3858MEDIUMAn out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remoteEPSS 6.4%CVE-2019-3859CRITICALAn out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A rEPSS 6.3%CVE-2019-3857HIGHAn integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUESEPSS 6.1%CVE-2019-3856HIGHAn integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requEPSS 6.1%CVE-2019-3861MEDIUMAn out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packetEPSS 5.1%CVE-2019-3860MEDIUMAn out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker EPSS 5.1%CVE-2019-3863HIGHA flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactivEPSS 3.4%