VendorsSSHssh22.0.8
Vulnerabilities

SSH Communications Security SSH2 2.0.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-1999-1029
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
Published 2001-09-12 · Modified
7.5EPSS 0.016
CVE-2002-1715
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.
Published 2005-06-21 · Modified
7.21 PoCEPSS 0.009
CVE-2000-0217
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
Published 2000-04-10 · Modified
5.1EPSS 0.010
CVE-1999-1231
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.
Published 2001-09-12 · Modified
5.0EPSS 0.015