Known vulnerabilities in openssh-server (Ubuntu package)
Vendor:
Canonical Ltd.
Software:
openssh-server (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:openssh-server_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
12
Public exploits:
5
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
1:8.9p1-3ubuntu0.16
1:9.6p1-3ubuntu13.18
1:9.6p1-3ubuntu13.16
1:8.9p1-3ubuntu0.15
1:9.6p1-3ubuntu13.15
1:8.9p1-3ubuntu0.14
1:8.2p1-4ubuntu0.13+esm1
1:10.0p1-5ubuntu5
1:9.9p1-3ubuntu3.2
1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.12
1:10.0p1-5ubuntu3
1:10.0p1-5ubuntu2
1:9.6p1-3ubuntu13.13
1:8.2p1-4ubuntu0.13
1:8.9p1-3ubuntu0.13
1:9.6p1-3ubuntu13.11
1:9.7p1-7ubuntu4.3
1:9.9p1-3ubuntu3.1
1:8.2p1-4ubuntu0.12
1:8.9p1-3ubuntu0.11
1:9.6p1-3ubuntu13.8
1:9.7p1-7ubuntu4.2
1:9.6p1-3ubuntu13.4
1:8.9p1-3ubuntu0.10
1:9.3p1-1ubuntu3.6
1:9.6p1-3ubuntu13.3
1:8.2p1-4ubuntu0.11
1:8.9p1-3ubuntu0.6
1:9.0p1-1ubuntu8.7
1:9.3p1-1ubuntu3.2
1:8.2p1-4ubuntu0.10
1:8.9p1-3ubuntu0.5
1:9.0p1-1ubuntu8.6
1:9.3p1-1ubuntu3.1
Ubuntu Pro (Infra-only)
1:7.6p1-4ubuntu0.7
1:7.6p1-4ubuntu0.6
1:7.6p1-4ubuntu0.5
1:7.2p2-4ubuntu2.10
8.2p1-4
8.0p1-6ubuntu0.1
8.0p1-6build1
7.6p1-4ubuntu0.4
7.6p1-4ubuntu0.3
7.6p1-4
7.2p2-4ubuntu2.9
7.2p2-4ubuntu2.8
7.2p2-4
6.6p1-2ubuntu2.13
6.6p1-2ubuntu1
5.9p1-5ubuntu1
5.9p1-5ubuntu1.10
1:8.0p1-6build1
1:8.0p1-4
1:7.7p1-4ubuntu0.3
1:7.6p1-4ubuntu0.3
1:7.2p2-4ubuntu2.8
1:7.9p1-10
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU107332 - Protection Mechanism Failure CVE-2025-32728 |
CWE-693 | Low | 1:8.2p1-4ubuntu0.13, 1:8.9p1-3ubuntu0.13, 1:9.6p1-3ubuntu13.11, 1:9.7p1-7ubuntu4.3, 1:9.9p1-3ubuntu3.1 | 10.04.2025 |
SB2025041009 SB2025041010 SB2025042478 and 14 more |
||
| #VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2025-26465 |
CWE-300 | Medium | Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2 | 18.02.2025 |
SB2025021815 SB2025021830 SB2025021833 and 49 more |
||
| #VU104034 - Improper input validation CVE-2025-26466 |
CWE-20 | Medium | 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2 | 18.02.2025 |
SB2025021815 SB2025021830 SB2025021840 and 25 more |
||
| #VU93514 - Exposure of sensitive information to an unauthorized actor CVE-2024-39894 |
CWE-200 | Low | 1:9.6p1-3ubuntu13.4 | 01.07.2024 |
SB2024070144 SB2024070956 SB2024071076 and 7 more |
||
| #VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-6387 |
CWE-362 | High | 1:8.9p1-3ubuntu0.10, 1:9.3p1-1ubuntu3.6, 1:9.6p1-3ubuntu13.3 | 01.07.2024 |
SB2024070144 SB2024070145 SB2024070152 and 89 more |
||
| #VU84792 - Inadequate Encryption Strength CVE-2023-51384 |
CWE-326 | Low | 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2 | 27.12.2023 |
SB2023121905 SB2023122710 SB2024010337 and 5 more |
||
| #VU84789 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-51385 |
CWE-78 | Medium | Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2 | 26.12.2023 |
SB2023121905 SB2023122710 SB2023122801 and 65 more |
||
| #VU84537 - Inadequate Encryption Strength CVE-2023-48795 |
CWE-326 | Low | Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.10, 1:8.9p1-3ubuntu0.5, 1:9.0p1-1ubuntu8.6, 1:9.3p1-1ubuntu3.1 | 19.12.2023 |
SB2023121903 SB2023121905 SB2023121906 and 343 more |
||
| #VU73775 - Credentials Management CVE-2023-28531 |
CWE-255 | Low | 1:8.2p1-4ubuntu0.10, 1:8.9p1-3ubuntu0.5, 1:9.0p1-1ubuntu8.6, 1:9.3p1-1ubuntu3.1 | 17.03.2023 |
SB2023031706 SB2023031713 SB2023062110 and 5 more |
||
| #VU58333 - Improper Privilege Management CVE-2021-41617 |
CWE-269 | Low | Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2 | 23.11.2021 |
SB2021092601 SB2021112330 SB2021120119 and 38 more |
||
| #VU14440 - Error Handling CVE-2018-15473 |
CWE-388 | Medium | 1:7.6p1-4ubuntu0.5 | 17.08.2018 |
SB2018081603 SB2018082309 SB2018090702 and 19 more |
||
| #VU14163 - NULL Pointer Dereference CVE-2016-10708 |
CWE-476 | Low | 1:7.6p1-4ubuntu0.5 | 31.07.2018 |
SB2017032008 SB2018072801 SB2018012101 and 7 more |