← All CVEs

CVE-2002-1359

high · 10

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

10
CVSS
80.2%
EPSS (exploit prob.)
100th
EPSS percentile
2002-12-23
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
ciscoios12.0s
ciscoios12.0st
ciscoios12.1e
ciscoios12.1ea
ciscoios12.1t
ciscoios12.2
ciscoios12.2s
ciscoios12.2t
fisshssh_client1.0a_for_windows
intersoftsecurenetterm5.4.1
netcompositeshellguard_ssh3.4.6
pragma_systemssecureshell2.0
puttyputty0.48
puttyputty0.49
puttyputty0.53
winscpwinscp2.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1359