Known vulnerabilities in libssh 0.8.7

Vendor: libssh
Software: libssh
Version: 0.8.7
Software CPE: cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting libssh version 0.8.7 libssh 0.8.7 is affected by 16 vulnerabilities: 8 medium, 8 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123156 - Out-of-bounds read
CVE-2026-0968
CWE-125 Medium
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123155 - Improper input validation
CVE-2026-0967
CWE-20 Low
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123154 - Buffer Underwrite ('Buffer Underflow')
CVE-2026-0966
CWE-124 Low
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123153 - Improper input validation
CVE-2026-0965
CWE-20 Low
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 9 more
#VU123151 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-0964
CWE-22 Medium
No
No
0.11.4 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU115175 - Missing release of memory after effective lifetime
CVE-2025-8277
CWE-401 Medium
No
No
0.11.3 12.09.2025 SB2025091210
SB2025091219
SB2025091220
and 11 more
#VU115173 - NULL Pointer Dereference
CVE-2025-8114
CWE-476 Medium
No
No
0.11.3 12.09.2025 SB2025091208
SB2025091219
SB2025091220
and 12 more
#VU115171 - Double Free
CVE-2025-5351
CWE-415 Low
No
No
0.10.2 12.09.2025 SB2025091206
SB2025091215
SB2025091222
and 4 more
#VU113840 - Use After Free
CVE-2025-4878
CWE-416 Low
No
No
0.11.2 12.08.2025 SB2025062451
SB2025081265
SB2025082012
and 5 more
#VU113839 - Integer overflow
CVE-2025-4877
CWE-190 Low
No
No
0.11.2 12.08.2025 SB2025062451
SB2025081265
SB2025082012
and 5 more
#VU111900 - Out-of-bounds read
CVE-2025-5318
CWE-125 Medium
No
No
0.11.2 24.06.2025 SB2025062451
SB2025062454
SB20250704157
and 61 more
#VU84540 - Unchecked Return Value
CVE-2023-6918
CWE-252 Low
No
No
0.9.8, 0.10.6 19.12.2023 SB2023121906
SB2023121910
SB2023121911
and 63 more
#VU84538 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6004
CWE-78 Medium
No
No
0.9.8, 0.10.6 19.12.2023 SB2023121905
SB2023121906
SB2023121910
and 58 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Public exploit available
No
0.9.8, 0.10.6 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU26756 - Resource Management Errors
CVE-2020-1730
CWE-399 Medium
No
No
0.8.9, 0.9.4 10.04.2020 SB2020041003
SB2020041004
SB2020041005
and 25 more
#VU23508 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-14889
CWE-78 Medium
No
No
0.8.8, 0.9.3 11.12.2019 SB2019121035
SB2019121107
SB2019121701
and 21 more