Vulnerabilities (CVE)

Filtered by vendor Pragma Systems Subscribe
Filtered by product Fortressssh
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-0132 1 Pragma Systems 1 Fortressssh 2017-08-08 5.0 MEDIUM N/A
Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.
CVE-2006-2421 1 Pragma Systems 1 Fortressssh 2017-07-20 7.5 HIGH N/A
Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSH_MSG_KEXINIT messages, which may cause an overflow when being logged. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.