Search CVE reports
101 – 110 of 50167 results
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command- line username, leading to injection.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.
3 affected packages
openssh, openssh-ssh1, openssh-gssapi
| Package | 24.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | Ignored |
| openssh-gssapi | Not in release |
(A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF ...)
2 affected packages
hdf5, r-bioc-rhdf5lib
| Package | 24.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
| r-bioc-rhdf5lib | Needs evaluation |
(Twisted is an event-based framework for internet applications, support ...)
1 affected package
twisted
| Package | 24.04 LTS |
|---|---|
| twisted | Needs evaluation |