Known vulnerabilities in openssh

Vendor: OpenAnolis
Software: openssh
Software CPE: cpe:2.3:o:openanolis:openssh:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 32
Public exploits: 9
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openssh openssh is affected by 32 known vulnerabilities: 1 critical, 2 high, 9 medium, 20 low Critical High Medium Low

Vulnerabilities (32)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137698 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59995
CWE-22 Low
No
No
9.6p1-11 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 8 more
#VU137699 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59996
CWE-22 Medium
No
No
9.6p1-11 15.07.2026 SB2026071535
SB20260715100
SB2026071797
and 7 more
#VU137700 - Argument Injection or Modification
CVE-2026-59997
CWE-88 Low
No
No
9.6p1-14 15.07.2026 SB2026071535
SB20260715100
SB2026081365
and 6 more
#VU137701 - Improper Access Control
CVE-2026-59999
CWE-284 Low
No
No
9.6p1-11 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 6 more
#VU137702 - Resource exhaustion
CVE-2026-60000
CWE-400 Medium
No
No
9.6p1-11 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 6 more
#VU137703 - Protection Mechanism Failure
CVE-2026-60001
CWE-693 Medium
No
No
9.6p1-11 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 6 more
#VU137704 - Use After Free
CVE-2026-60002
CWE-416 Low
No
No
9.6p1-12 15.07.2026 SB2026071535
SB20260715100
SB2026071797
and 4 more
#VU128473 - Improper input validation
CVE-2026-35386
CWE-20 Low
No
No
8.0p1-29.0.1, 9.6p1-13 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 16 more
#VU128474 - Improper Access Control
CVE-2026-35414
CWE-284 Low
No
No
8.0p1-29.0.1, 9.6p1-5 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 24 more
#VU128475 - Improper Privilege Management
CVE-2026-35385
CWE-269 Low
No
No
8.0p1-29.0.1, 9.6p1-9 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 30 more
#VU128476 - Improper Access Control
CVE-2026-35387
CWE-284 Low
No
No
8.0p1-29.0.1, 9.6p1-9 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 17 more
#VU128477 - Improper Authorization
CVE-2026-35388
CWE-285 Low
No
No
8.0p1-29.0.1, 9.6p1-6 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 19 more
#VU124014 - Resource Management Errors
CVE-2026-3497
CWE-399 Low
No
No
8.0p1-28.0.1, 9.6p1-9 13.03.2026 SB2026031837
SB2026031838
SB2026031839
and 19 more
#VU116883 - Improper Neutralization of Null Byte or NUL Character
CVE-2025-61985
CWE-158 Low
No
No
8.0p1-27.0.1, 9.6p1-4 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 25 more
#VU116882 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-61984
CWE-78 Low
No
No
8.0p1-27.0.1, 9.6p1-4 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 27 more
#VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2025-26465
CWE-300 Medium
No
No
8.0p1-26.0.1, 9.3p2-3 18.02.2025 SB2025021815
SB2025021830
SB2025021833
and 49 more
#VU104034 - Improper input validation
CVE-2025-26466
CWE-20 Medium
Available
No
9.6p1-3 18.02.2025 SB2025021815
SB2025021830
SB2025021840
and 25 more
#VU93515 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2006-5051
CWE-362 Critical
No
No
9.3p2-2, 9.6p1-2 01.07.2024 SB2006092801
SB2024071109
SB2024071110
and 5 more
#VU93514 - Exposure of sensitive information to an unauthorized actor
CVE-2024-39894
CWE-200 Low
No
No
9.6p1-3 01.07.2024 SB2024070144
SB2024070956
SB2024071076
and 7 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
8.0p1-20.0.4 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more


Showing elements 1 - 20 out of 32