Threats Tagged 'cve-2025-4877'
View all threats tagged with 'cve-2025-4877'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-4877'
Click on any threat for detailed analysis and mitigation recommendations
0 There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function. In such cases the bin_to_base64() function can experience an integer overflow leading to a memory under allocation, when that happens it's possible that the program perform out of bounds write leading to a heap corruption. This issue affects only 32-bits builds of libssh. Join the discussion | CVE Database V5 | 08/20/2025, 12:19:18 UTC Added: 08/20/2025, 12:32:47 UTC |
0 Ronald Crane discovered that libssh incorrectly handled certain base64 conversions. An attacker could use this issue to cause libssh to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-4877) Ronald Crane discovered that libssh incorrectly handled the privatekey_from_file() function. An attacker could use this issue to cause libssh to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-4878) Ronald Crane discovered that libssh incorrectly handled certain memory operations in the sftp server. An attacker could possibly use this issue to cause libssh to crash, resulting in a denial of service. (CVE-2025-5318, CVE-2025-5449) Ronald Crane discovered that libssh incorrectly handled exporting keys. An attacker could possibly use this issue to cause libssh to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5351) Ronald Crane discovered that libssh incorrectly handled the ssh_kdf() function. An attacker could use this issue to cause libssh to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-5372) Ronald Crane discovered that libssh incorrectly handled the ChaCha20 cipher. An attacker could possibly use this issue to cause libssh to use partially initialized cypher content. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987) Join the discussion | GCVE Database | 07/07/2025, 12:29:26 UTC Added: 06/02/2026, 21:43:34 UTC |
Showing 1 to 2 of 2 results