Known vulnerabilities in pam_ssh_agent_auth
Vendor:
openEuler
Software:
pam_ssh_agent_auth
Software CPE:
cpe:2.3:o:openeuler:pam_ssh_agent_auth:*:*:*:*:*:openeuler:*:*
Website:
https://www.openeuler.org/
Total vulnerabilities:
32
Public exploits:
7
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
0.10.4-5.21
0.10.4-4.49
0.10.4-5.20
0.10.4-5.23
0.10.4-5.22
0.10.3-9.42
0.10.4-4.48
0.10.4-5.19
0.10.3-9.39
0.10.4-4.46
0.10.4-5.17
0.10.4-5.13
0.10.4-4.9
0.10.3-9.33
0.10.4-4.37
0.10.4-5.9
0.10.4-4.6
0.10.4-4.35
0.10.4-4.8
0.10.3-9.31
0.10.4-4.34
0.10.4-4.5
0.10.4-4.32
0.10.4-4.31
0.10.4-4.4
0.10.4-4.26
0.10.3-9.29
0.10.4-4.25
0.10.4-4.23
0.10.3-9.28
0.10.3-9.27
0.10.4-4.18
0.10.4-4.16
0.10.4-4.17
0.10.3-9.16
0.10.3-9.15
0.10.3-9.14
0.10.3-9.9
0.10.3-9.1
Vulnerabilities (32)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146881 - Improper Access Control CVE-2026-73281 |
CWE-284 | Low | 0.10.4-5.21 | 03.09.2026 |
SB2026090365 SB2026090366 SB2026090513 and 2 more |
||
| #VU146882 - Use After Free CVE-2026-73282 |
CWE-416 | Low | 0.10.4-5.23 | 03.09.2026 |
SB2026090365 SB2026090366 SB2026092042 and 2 more |
||
| #VU146883 - Improper Access Control CVE-2026-73283 |
CWE-284 | Low | 0.10.4-5.23 | 03.09.2026 |
SB2026090365 SB2026090366 SB2026092042 and 1 more |
||
| #VU137698 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-59995 |
CWE-22 | Low | 0.10.3-9.39, 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22 | 15.07.2026 |
SB2026071535 SB20260715100 SB20260728131 and 10 more |
||
| #VU137699 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-59996 |
CWE-22 | Medium | 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22 | 15.07.2026 |
SB2026071535 SB20260715100 SB2026071797 and 7 more |
||
| #VU137700 - Argument Injection or Modification CVE-2026-59997 |
CWE-88 | Low | 0.10.3-9.39, 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22 | 15.07.2026 |
SB2026071535 SB20260715100 SB2026081365 and 6 more |
||
| #VU137701 - Improper Access Control CVE-2026-59999 |
CWE-284 | Low | 0.10.3-9.39, 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22 | 15.07.2026 |
SB2026071535 SB20260715100 SB20260728131 and 9 more |
||
| #VU137702 - Resource exhaustion CVE-2026-60000 |
CWE-400 | Medium | 0.10.3-9.42, 0.10.4-4.48, 0.10.4-5.19, 0.10.4-5.22 | 15.07.2026 |
SB2026071535 SB20260715100 SB20260728131 and 6 more |
||
| #VU137703 - Protection Mechanism Failure CVE-2026-60001 |
CWE-693 | Medium | 0.10.3-9.42, 0.10.4-4.48, 0.10.4-5.19, 0.10.4-5.22 | 15.07.2026 |
SB2026071535 SB20260715100 SB20260728131 and 7 more |
||
| #VU137704 - Use After Free CVE-2026-60002 |
CWE-416 | Low | 0.10.3-9.42, 0.10.4-4.49, 0.10.4-5.20, 0.10.4-5.23 | 15.07.2026 |
SB2026071535 SB20260715100 SB2026071797 and 10 more |
||
| #VU128473 - Improper input validation CVE-2026-35386 |
CWE-20 | Low | 0.10.4-5.13 | 29.04.2026 |
SB2026042988 SB2026042990 SB2026042992 and 16 more |
||
| #VU128474 - Improper Access Control CVE-2026-35414 |
CWE-284 | Low | 0.10.4-5.13 | 29.04.2026 |
SB2026042988 SB2026042990 SB2026042992 and 24 more |
||
| #VU128475 - Improper Privilege Management CVE-2026-35385 |
CWE-269 | Low | 0.10.4-5.13 | 29.04.2026 |
SB2026042988 SB2026042990 SB2026042992 and 33 more |
||
| #VU128476 - Improper Access Control CVE-2026-35387 |
CWE-284 | Low | 0.10.4-5.13 | 29.04.2026 |
SB2026042988 SB2026042990 SB2026042992 and 17 more |
||
| #VU128477 - Improper Authorization CVE-2026-35388 |
CWE-285 | Low | 0.10.4-5.13 | 29.04.2026 |
SB2026042988 SB2026042990 SB2026042992 and 19 more |
||
| #VU124014 - Resource Management Errors CVE-2026-3497 |
CWE-399 | Low | 0.10.4-5.13 | 13.03.2026 |
SB2026031837 SB2026031838 SB2026031839 and 19 more |
||
| #VU116883 - Improper Neutralization of Null Byte or NUL Character CVE-2025-61985 |
CWE-158 | Low | 0.10.3-9.33, 0.10.4-4.9, 0.10.4-4.37, 0.10.4-5.9 | 10.10.2025 |
SB2025101008 SB2025103199 SB20251031100 and 26 more |
||
| #VU116882 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-61984 |
CWE-78 | Low | 0.10.3-9.33, 0.10.4-4.9, 0.10.4-4.37, 0.10.4-5.9 | 10.10.2025 |
SB2025101008 SB2025103199 SB20251031100 and 28 more |
||
| #VU107332 - Protection Mechanism Failure CVE-2025-32728 |
CWE-693 | Low | 0.10.3-9.31, 0.10.4-4.6, 0.10.4-4.8, 0.10.4-4.35 | 10.04.2025 |
SB2025041009 SB2025041010 SB2025042478 and 14 more |
||
| #VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2025-26465 |
CWE-300 | Medium | 0.10.3-9.31, 0.10.4-4.5, 0.10.4-4.8, 0.10.4-4.34 | 18.02.2025 |
SB2025021815 SB2025021830 SB2025021833 and 49 more |
Showing elements 1 - 20 out of 32