CVE Vulnerabilities in 2017

29 documented vulnerabilities published in 2017.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2017

All CVEs from 2017

CVE-2016-6210
5.9 medium

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.

Openbsd Openssh Feb 13, 2017
CVE-2016-10012
7.8 high

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to th

Openbsd Openssh Jan 5, 2017
CVE-2016-10011
6.2 medium

authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.

Openbsd Openssh Jan 5, 2017
CVE-2016-10010
7.0 high

sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.

Openbsd Openssh Jan 5, 2017
CVE-2016-10009
7.3 high

Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.

Openbsd Openssh Jan 5, 2017