یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 18 نتیجه
فیلترهای فعال دسته: network پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

کم EPSS 79.7% اولویت 40

CVE-2023-38408 — https://errata.almalinux.org/8/ALSA-2026-69266.html

سلام، شما یک ایمیل به‌روزرسانی امنیتی AlmaLinux دریافت می‌کنید زیرا برای دریافت اعلان‌های خطا از AlmaLinux مشترک شده‌اید. AlmaLinux: 8 نوع: امنیتی شدت: مهم تاریخ انتشار: 2026-09-21 خلاصه: OpenSSH یک پیاده‌سازی پروتکل SSH است که توسط تعدادی از سیستم‌عامل‌های لینوکس، یونیکس و مشابه پشتیبانی می‌شود. این شامل فایل‌های اصلی لازم برای هر دو کلاینت OpenSSH و سرور…

OpenSSH / OpenSSH AlmaLinux / AlmaLinux
2026-09-2100:00
2 منبع · 2 رسمی اعتماد خوب · 76/100 کیفیت خوب · 78/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 9

OpenSSH Security Advisory

March 7, 2002: OpenSSH 3.1 and newer are not vulnerable to "March 7, 2002: Off-by-one error in the channel code", OpenSSH Security Advisory.

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
کم اولویت 16

OpenSSH Security Advisory

March 29, 2002: OpenSSH 3.2.1 and newer are not vulnerable to "April 21, 2002: Buffer overflow in AFS/Kerberos token passing code", OpenSSH Security Advisory: Versions prior to OpenSSH 3.2.1 allow privileged access if AFS/Kerberos token passing is compiled in and enabled (either in the system or in sshd_config).

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 61/100 کیفیت خوب · 71/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 9

OpenSSH Security Advisory

June 26, 2002: OpenSSH 3.4 and newer are not vulnerable to "June 26, 2002: OpenSSH Remote Challenge Vulnerability", OpenSSH Security Advisory.

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 9

CA-2003-24

September 16, 2003: OpenSSH 3.7.1 and newer are not vulnerable to "September 16, 2003: OpenSSH Buffer Management bug", OpenSSH Security Advisory and CERT Advisory CA-2003-24.

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 9

OpenSSH Security Advisory

September 16, 2003: OpenSSH 3.7.1 and newer are not vulnerable to "September 16, 2003: OpenSSH Buffer Management bug", OpenSSH Security Advisory and CERT Advisory CA-2003-24.

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 9

OpenSSH Security Advisory

September 16, 2003: Portable OpenSSH 3.7.1p2 and newer are not vulnerable to "September 23, 2003: Portable OpenSSH Multiple PAM vulnerabilities", OpenSSH Security Advisory. (This issue does not affect OpenBSD versions)

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص EPSS 0.5% اولویت 10

CVE-2006-0225 — OpenSSH 4.3 release notes

February 1, 2006: OpenSSH 4.3 and newer are not vulnerable to shell metacharacter expansion in scp(1) local-local and remote-remote copies (CVE-2006-0225), as described in the OpenSSH 4.3 release notes.

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 61/100 کیفیت خوب · 71/100 داده تازه جزئیات و راهکار رفع
نامشخص EPSS 0.3% اولویت 10

CVE-2008-1483 — OpenSSH 5.0 release notes

April 3, 2008: OpenSSH 5.0 and newer are not vulnerable to the X11 hijacking attack described in CVE-2008-1483 and the OpenSSH 5.0 release notes.

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 61/100 کیفیت خوب · 71/100 داده تازه جزئیات و راهکار رفع
کم EPSS 20.9% اولویت 19

CVE-2016-0778 — CVE-2016-0778

January 14, 2016 OpenSSH clients between versions 5.4 and 7.1 are vulnerable to information disclosure that may allow a malicious server to retrieve information including under some circumstances, user's private keys. This may be mitigated by adding the undocumented config option UseRoaming no to ssh_config. For more information see CVE-2016-0777 and…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد متوسط · 53/100 نیازمند توجه · 56/100 داده قدیمی جزئیات و راهکار رفع
کم EPSS 63.5% اولویت 34

CVE-2016-0777 — CVE-2016-0777

January 14, 2016 OpenSSH clients between versions 5.4 and 7.1 are vulnerable to information disclosure that may allow a malicious server to retrieve information including under some circumstances, user's private keys. This may be mitigated by adding the undocumented config option UseRoaming no to ssh_config. For more information see CVE-2016-0777 and…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 64/100 کیفیت خوب · 77/100 داده تازه جزئیات و راهکار رفع
کم EPSS 99.5% اولویت 41

CVE-2024-6387 — Qualys Security Advisory Team

July 1, 2024 sshd(8) in Portable OpenSSH versions 8.5p1 to 9.7p1 (inclusive). Race condition resulting in potential remote code execution. A race condition in sshd(8) could allow remote code execution as root on non-OpenBSD systems. This attack could be prevented by disabling the login grace timeout (LoginGraceTime=0 in sshd_config) though this makes…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 64/100 کیفیت خوب · 77/100 داده تازه جزئیات و راهکار رفع
کم اولویت 16

release notes

July 1, 2024 sshd(8) in Portable OpenSSH versions 8.5p1 to 9.7p1 (inclusive). Race condition resulting in potential remote code execution. A race condition in sshd(8) could allow remote code execution as root on non-OpenBSD systems. This attack could be prevented by disabling the login grace timeout (LoginGraceTime=0 in sshd_config) though this makes…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 61/100 کیفیت خوب · 71/100 داده تازه جزئیات و راهکار رفع
کم EPSS 7.4% اولویت 19

CVE-2025-26465 — Qualys Security Advisory Team

February 18, 2025 ssh(1) in OpenSSH versions 6.8p1 to 9.9p1 (inclusive). VerifyHostKeyDNS server impersonation. A logic error in ssh(1) allowed an on-path attacker to impersonate any server when the VerifyHostKeyDNS option is enabled. This option is disabled by default. This vulnerability has been assigned CVE-2025-26465. For more information, please refer…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 64/100 کیفیت خوب · 77/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 8

OpenSSH Security Advisory

May 21, 2001: OpenSSH 2.9.9 and newer are not vulnerable to "Sep 26, 2001: Weakness in OpenSSH's source IP based access control for SSH protocol v2 public key authentication.", OpenSSH Security Advisory.

OpenSSH / OpenSSH
2001-05-2100:00
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 8

OpenBSD Security Advisory

November 6, 2000: OpenSSH 2.3.1, a development snapshot which was never released, was vulnerable to "Feb 8, 2001: Authentication By-Pass Vulnerability in OpenSSH-2.3.1", OpenBSD Security Advisory. In protocol 2, authentication could be bypassed if public key authentication was permitted. This problem does exist only in OpenSSH 2.3.1, a three week internal…

OpenSSH / OpenSSH
2001-02-0800:00
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 8

Crimelabs Security Note CLABS200101

OpenSSH was never vulnerable to the "Feb 5, 2001: SSH-1 Brute Force Password Vulnerability", Crimelabs Security Note CLABS200101.

OpenSSH / OpenSSH
2001-02-0500:00
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع