Known vulnerabilities in openssh-server (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:openssh-server_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 12
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openssh-server (Ubuntu package) openssh-server (Ubuntu package) is affected by 12 known vulnerabilities: 1 high, 4 medium, 7 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107332 - Protection Mechanism Failure
CVE-2025-32728
CWE-693 Low
No
No
1:8.2p1-4ubuntu0.13, 1:8.9p1-3ubuntu0.13, 1:9.6p1-3ubuntu13.11, 1:9.7p1-7ubuntu4.3, 1:9.9p1-3ubuntu3.1 10.04.2025 SB2025041009
SB2025041010
SB2025042478
and 14 more
#VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2025-26465
CWE-300 Medium
No
No
Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2 18.02.2025 SB2025021815
SB2025021830
SB2025021833
and 49 more
#VU104034 - Improper input validation
CVE-2025-26466
CWE-20 Medium
Available
No
1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2 18.02.2025 SB2025021815
SB2025021830
SB2025021840
and 25 more
#VU93514 - Exposure of sensitive information to an unauthorized actor
CVE-2024-39894
CWE-200 Low
No
No
1:9.6p1-3ubuntu13.4 01.07.2024 SB2024070144
SB2024070956
SB2024071076
and 7 more
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
1:8.9p1-3ubuntu0.10, 1:9.3p1-1ubuntu3.6, 1:9.6p1-3ubuntu13.3 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU84792 - Inadequate Encryption Strength
CVE-2023-51384
CWE-326 Low
No
No
1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2 27.12.2023 SB2023121905
SB2023122710
SB2024010337
and 5 more
#VU84789 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-51385
CWE-78 Medium
Available
No
Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2 26.12.2023 SB2023121905
SB2023122710
SB2023122801
and 65 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.10, 1:8.9p1-3ubuntu0.5, 1:9.0p1-1ubuntu8.6, 1:9.3p1-1ubuntu3.1 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU73775 - Credentials Management
CVE-2023-28531
CWE-255 Low
No
No
1:8.2p1-4ubuntu0.10, 1:8.9p1-3ubuntu0.5, 1:9.0p1-1ubuntu8.6, 1:9.3p1-1ubuntu3.1 17.03.2023 SB2023031706
SB2023031713
SB2023062110
and 5 more
#VU58333 - Improper Privilege Management
CVE-2021-41617
CWE-269 Low
No
No
Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2 23.11.2021 SB2021092601
SB2021112330
SB2021120119
and 38 more
#VU14440 - Error Handling
CVE-2018-15473
CWE-388 Medium
Available
No
1:7.6p1-4ubuntu0.5 17.08.2018 SB2018081603
SB2018082309
SB2018090702
and 19 more
#VU14163 - NULL Pointer Dereference
CVE-2016-10708
CWE-476 Low
No
No
1:7.6p1-4ubuntu0.5 31.07.2018 SB2017032008
SB2018072801
SB2018012101
and 7 more