QSearchQSearch

CVE-2016-10010

7.0 HIGH

sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local...

Published: 2017-01-05 · Last updated: 2026-05-29

Severity and scoring

CVSS
7.0 HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-264, CWE-269

Affected products

VendorProduct
openbsdopenssh

Description

sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-3497 Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions (7.5 HIGH)
  • CVE-2023-51767 OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer ... (7.0 HIGH)
  • CVE-2023-51384 In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied (5.5 MEDIUM)
  • CVE-2023-28531 ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints (9.8 CRITICAL)
  • CVE-2023-25136 OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling (6.5 MEDIUM)

Same CWE

  • CVE-2026-11616 The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28 (8.8 HIGH)
  • CVE-2026-41974 Permission control vulnerability in service notifications (3.6 LOW)
  • CVE-2026-44119 Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with th... (5.5 MEDIUM)
  • CVE-2026-11423 A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied fil...
  • CVE-2025-5088 An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster (8.3 HIGH)