Known vulnerabilities in openssh-ldap

Vendor: openEuler
Software: openssh-ldap
Software CPE: cpe:2.3:o:openeuler:openssh-ldap:*:*:*:*:*:openeuler:*:*
Total vulnerabilities: 12
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 7.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openssh-ldap openssh-ldap is affected by 12 known vulnerabilities: 4 medium, 8 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137698 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59995
CWE-22 Low
No
No
8.2p1-39 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 11 more
#VU137700 - Argument Injection or Modification
CVE-2026-59997
CWE-88 Low
No
No
8.2p1-39 15.07.2026 SB2026071535
SB20260715100
SB2026081365
and 7 more
#VU137701 - Improper Access Control
CVE-2026-59999
CWE-284 Low
No
No
8.2p1-39 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 10 more
#VU137702 - Resource exhaustion
CVE-2026-60000
CWE-400 Medium
No
No
8.2p1-42 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 7 more
#VU137703 - Protection Mechanism Failure
CVE-2026-60001
CWE-693 Medium
No
No
8.2p1-42 15.07.2026 SB2026071535
SB20260715100
SB20260728131
and 10 more
#VU137704 - Use After Free
CVE-2026-60002
CWE-416 Low
No
No
8.2p1-42 15.07.2026 SB2026071535
SB20260715100
SB2026071797
and 10 more
#VU116883 - Improper Neutralization of Null Byte or NUL Character
CVE-2025-61985
CWE-158 Low
No
No
8.2p1-33 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 26 more
#VU116882 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-61984
CWE-78 Low
No
No
8.2p1-33 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 28 more
#VU107332 - Protection Mechanism Failure
CVE-2025-32728
CWE-693 Low
No
No
8.2p1-31 10.04.2025 SB2025041009
SB2025041010
SB2025042478
and 14 more
#VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2025-26465
CWE-300 Medium
No
No
8.2p1-31 18.02.2025 SB2025021815
SB2025021830
SB2025021833
and 49 more
#VU84789 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-51385
CWE-78 Medium
Available
No
8.2p1-28 26.12.2023 SB2023121905
SB2023122710
SB2023122801
and 65 more
#VU58333 - Improper Privilege Management
CVE-2021-41617
CWE-269 Low
No
No
8.2p1-14 23.11.2021 SB2021092601
SB2021112330
SB2021120119
and 38 more