djm

7 exploits Active since Jan 2017
CVE-2016-10009 WRITEUP HIGH WRITEUP
OpenSSH < 7.3 - Remote Code Execution via Forwarded SSH-Agent PKCS#11 Module Loading
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.
CVSS 7.3
CVE-2016-10010 WRITEUP HIGH WRITEUP
OpenSSH <7.4 - Privilege Escalation
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.
CVSS 7.0
CVE-2018-15473 WRITEUP MEDIUM WRITEUP
OpenSSH < 7.7 - User Enumeration via Authentication Request Timing
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
CVSS 5.3
CVE-2023-38408 WRITEUP CRITICAL WRITEUP
OpenSSH < 9.3p2 - Remote Code Execution via PKCS#11 Untrusted Search Path
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVSS 9.8
CVE-2023-38408 WRITEUP CRITICAL WRITEUP
OpenSSH < 9.3p2 - Remote Code Execution via PKCS#11 Untrusted Search Path
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVSS 9.8
CVE-2023-38408 WRITEUP CRITICAL WRITEUP
OpenSSH < 9.3p2 - Remote Code Execution via PKCS#11 Untrusted Search Path
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVSS 9.8
CVE-2017-15906 WRITEUP MEDIUM WRITEUP
OpenSSH < 7.6 - Unauthenticated Arbitrary File Creation in Readonly Mode
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
CVSS 5.3