Known vulnerabilities in openssh (Alpine package)

Software CPE: cpe:2.3:o:alpine:openssh_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 22
Public exploits: 8
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openssh (Alpine package) openssh (Alpine package) is affected by 22 known vulnerabilities: 2 high, 7 medium, 13 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU33998 - Improper input validation
CVE-2015-6563
CWE-20 Low
No
No
6.4_p1-r4 05.08.2020 SB2015082416
SB2015082608
SB2015121404
and 6 more
#VU32937 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-14145
CWE-327 Medium
No
No
- 30.07.2020 SB2020073043
SB2020121421
SB2021052625
and 11 more
#VU16990 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2019-6109
CWE-451 Low
No
No
7.5_p1-r4 15.01.2019 SB2019011505
SB2019012805
SB2019012904
and 13 more
#VU16988 - Improper input validation
CVE-2019-6111
CWE-20 Low
Available
No
7.5_p1-r4 15.01.2019 SB2019011505
SB2019012805
SB2019012904
and 17 more
#VU16946 - Improper Access Control
CVE-2018-20685
CWE-284 Low
No
No
7.5_p1-r4 10.01.2019 SB2019011505
SB2019012805
SB2019012904
and 14 more
#VU14440 - Error Handling
CVE-2018-15473
CWE-388 Medium
Available
No
7.4_p1-r2 17.08.2018 SB2018081603
SB2018082309
SB2018090702
and 19 more
#VU9333 - Permissions, Privileges, and Access Controls
CVE-2017-15906
CWE-264 Low
No
No
7.2_p2-r5 15.11.2017 SB2017111501
SB2017111502
SB2018010803
and 14 more
#VU2075 - Memory corruption
CVE-2016-10012
CWE-119 Low
No
No
6.8_p1-r9 21.12.2016 SB2016122003
SB2016122004
SB2016122201
and 13 more
#VU2068 - Permissions, Privileges, and Access Controls
CVE-2016-10011
CWE-264 Low
No
No
6.8_p1-r9 21.12.2016 SB2016122003
SB2016122201
SB2016122401
and 9 more
#VU2053 - Permissions, Privileges, and Access Controls
CVE-2016-10010
CWE-264 Low
Available
No
6.8_p1-r9 21.12.2016 SB2016122003
SB2017011102
SB2016122201
and 7 more
#VU1482 - Use After Free
CVE-2015-6564
CWE-416 Low
No
No
6.4_p1-r4 21.12.2016 SB2019070910
SB2015082401
SB2015082609
and 8 more
#VU2015 - Improper input validation
CVE-2016-10009
CWE-20 Low
Available
No
6.8_p1-r9 19.12.2016 SB2016122003
SB2017011102
SB2016122004
and 21 more
#VU719 - Improper Access Control
CVE-2016-0778
CWE-284 High
No
No
6.6_p1-r7 03.10.2016 SB2016011401
SB2016011402
SB2016011501
and 17 more
#VU718 - Improper Access Control
CVE-2016-0777
CWE-284 Low
No
No
6.6_p1-r7 03.10.2016 SB2016011401
SB2016011402
SB2016011501
and 19 more
#VU255 - Exposure of sensitive information to an unauthorized actor
CVE-2016-6210
CWE-200 Medium
Available
No
6.7_p1-r5 02.08.2016 SB2016080201
SB2016080202
SB2016080203
and 16 more
#VU252 - Resource exhaustion
CVE-2016-6515
CWE-400 Medium
Available
No
6.7_p1-r6 02.08.2016 SB2016080201
SB2016080202
SB2016080203
and 11 more
#VU33811 - Improper input validation
CVE-2016-3115
CWE-20 Medium
Available
No
6.6_p1-r8 22.03.2016 SB2016032202
SB2016032208
SB2016031605
and 10 more
#VU33287 - Permissions, Privileges, and Access Controls
CVE-2015-6565
CWE-264 Low
Available
No
6.4_p1-r4 24.08.2015 SB2015082414
SB2015082610
#VU33288 - Permissions, Privileges, and Access Controls
CVE-2015-5600
CWE-264 High
No
No
6.4_p1-r3 03.08.2015 SB2015080301
SB2015073006
SB2015121404
and 6 more
#VU33294 - Improper input validation
CVE-2014-2653
CWE-20 Medium
No
No
5.9_p1-r4 27.03.2014 SB2014032701
SB2014041810
SB2014070907
and 1 more


Showing elements 1 - 20 out of 22