Vulnerabilities
Vulnerable Software
Security Vulnerabilities
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
CVSS Score
3.1
EPSS Score
0.002
Published
2026-07-21
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-07-21
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-07-21
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-07-21
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-07-21
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
CVSS Score
5.9
EPSS Score
0.003
Published
2026-07-21
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-07-21
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
CVSS Score
3.9
EPSS Score
0.001
Published
2026-07-21
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVSS Score
9.1
EPSS Score
0.002
Published
2026-07-21
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-07-21


Contact Us

Shodan ® - All rights reserved