Known vulnerabilities in libssh

Vendor: OpenAnolis
Software: libssh
Software CPE: cpe:2.3:o:openanolis:libssh:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 24
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libssh libssh is affected by 24 known vulnerabilities: 2 high, 8 medium, 14 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139533 - Use After Free
CVE-2026-59850
CWE-416 Low
No
No
0.9.6-17.0.1, 0.10.5-16 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 10 more
#VU139531 - Resource exhaustion
CVE-2026-59848
CWE-400 Low
No
No
0.9.6-17.0.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 5 more
#VU139530 - Improper Validation of Integrity Check Value
CVE-2026-59847
CWE-354 Medium
No
No
0.9.6-17.0.1, 0.10.5-17 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 10 more
#VU139529 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-59846
CWE-78 Low
No
No
0.9.6-17.0.1 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 4 more
#VU139527 - Improper input validation
CVE-2026-59844
CWE-20 Low
No
No
0.9.6-17.0.1, 0.10.5-19 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 10 more
#VU139526 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-59843
CWE-835 Low
No
No
0.9.6-17.0.1, 0.10.5-20 27.07.2026 SB20260727145
SB20260728153
SB2026080402
and 11 more
#VU139524 - Improper Check or Handling of Exceptional Conditions
CVE-2026-59845
CWE-703 Low
No
No
0.9.6-17.0.1, 0.10.5-15 27.07.2026 SB20260727145
SB20260728129
SB20260728153
and 11 more
#VU123156 - Out-of-bounds read
CVE-2026-0968
CWE-125 Medium
No
No
0.10.5-13 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123155 - Improper input validation
CVE-2026-0967
CWE-20 Low
No
No
0.10.5-13 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123154 - Buffer Underwrite ('Buffer Underflow')
CVE-2026-0966
CWE-124 Low
No
No
0.10.5-13 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU123151 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-0964
CWE-22 Medium
No
No
0.10.5-13 24.02.2026 SB2026022406
SB2026022408
SB2026022422
and 10 more
#VU115175 - Missing release of memory after effective lifetime
CVE-2025-8277
CWE-401 Medium
No
No
0.10.5-12 12.09.2025 SB2025091210
SB2025091219
SB2025091220
and 11 more
#VU115173 - NULL Pointer Dereference
CVE-2025-8114
CWE-476 Medium
No
No
0.10.5-11 12.09.2025 SB2025091208
SB2025091219
SB2025091220
and 12 more
#VU115172 - Return of Wrong Status Code
CVE-2025-5987
CWE-393 Low
No
No
0.10.5-8 12.09.2025 SB2025091207
SB2025091215
SB2025091222
and 17 more
#VU115171 - Double Free
CVE-2025-5351
CWE-415 Low
No
No
0.10.5-9 12.09.2025 SB2025091206
SB2025091215
SB2025091222
and 4 more
#VU114093 - Incorrect Calculation
CVE-2025-5372
CWE-682 Low
No
No
0.9.6-16.0.1, 0.10.5-7 14.08.2025 SB2025081494
SB2025081495
SB2025081532
and 21 more
#VU113840 - Use After Free
CVE-2025-4878
CWE-416 Low
No
No
0.10.5-10 12.08.2025 SB2025062451
SB2025081265
SB2025082012
and 5 more
#VU111900 - Out-of-bounds read
CVE-2025-5318
CWE-125 Medium
No
No
0.9.6-15.0.1, 0.10.5-6 24.06.2025 SB2025062451
SB2025062454
SB20250704157
and 61 more
#VU84540 - Unchecked Return Value
CVE-2023-6918
CWE-252 Low
No
No
0.9.6-12, 0.10.5-3 19.12.2023 SB2023121906
SB2023121910
SB2023121911
and 63 more
#VU84538 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6004
CWE-78 Medium
No
No
0.9.6-12, 0.10.5-3 19.12.2023 SB2023121905
SB2023121906
SB2023121910
and 58 more


Showing elements 1 - 20 out of 24