Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-0778

36
FAUCET Score

CVE-2016-0778 is a heap-based buffer overflow vulnerability in OpenSSH client versions 5.x, 6.x, and 7.x before 7.1p2, specifically within the roaming_read and roaming_write functions. This flaw, triggered when certain proxy and forward options are enabled, allows remote servers to cause a denial of service or potentially other unspecified impacts by requesting numerous forwardings. The vulnerability carries a high severity CVSS score of 8.1, indicating a network-based attack with high impact on confidentiality, integrity, and availability, though it has high attack complexity. Its EPSS score is low, suggesting a low probability of exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article identified.

Impacted Technologies

VendorProductVersion(s)CPE
7CPE matchmatch criteria
cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
11.3CPE matchmatch criteria
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
5.4CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:5.4:*:*:*:*:*:*:*
5.4CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:5.4:p1:*:*:*:*:*:*
5.5CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:5.5:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.1HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
20.90%
Probability of exploitation in next 30 days
EPSS Percentile
97.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.2090 is in the 87th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

latchsetpatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
nodejspatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
openldappatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssh-0:6.6.1p1-23.el7_2
View patch
traefikpatch availablevia llm_extracted
Fixed in: 7.1p2
View patch
applevendor investigatingvia nvd_reference
View patch

Vendor Advisories (5)

redhatCVE-2016-0778Low

OpenSSH: Client buffer-overflow when using roaming connections

Jan 14, 2016
openldapllm-openldap-b3332402b2969b0d

Information disclosure vulnerability in OpenSSH clients.

Jan 14, 2016
traefikllm-traefik-d6a6f9be33357f1bHIGH

Information disclosure in OpenSSH clients via malicious server

Jan 14, 2016
nodejsllm-nodejs-236af00f01df7b46

OpenSSH clients vulnerable to information disclosure that may allow a malicious server to retrieve private keys.

Jan 14, 2016
latchsetllm-latchset-8ec4832f5a1a3c4c

Information disclosure vulnerability in OpenSSH clients.

Jan 14, 2016

References

kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.apple.com / archives/security-announce/2016/Mar/msg00004.html
Mailing ListRelease NotesThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-February/176516.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-January/176349.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00008.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00009.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00013.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-01/msg00014.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html
Third Party AdvisoryVDB Entry
blogs.sophos.com / 2016/02/17/utm-up2date-9-354-released
Release NotesVendor Advisory
blogs.sophos.com / 2016/02/29/utm-up2date-9-319-released
Release NotesVendor Advisory
bto.bluecoat.com / security-advisory/sa109
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-412672.pdf
seclists.org / fulldisclosure/2016/Jan/44
Mailing ListThird Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
security.gentoo.org / glsa/201601-01
Third Party Advisory
support.apple.com / HT206167
Vendor Advisory
debian.org / security/2016/dsa-3446
Third Party Advisory
openssh.com / txt/release-7.1p2
PatchRelease NotesVendor Advisory
openwall.com / lists/oss-security/2016/01/14/7
ExploitMailing ListTechnical DescriptionThird Party Advisory
oracle.com / technetwork/topics/security/bulletinoct2015-2511968.html
Third Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
securityfocus.com / archive/1/537295/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/80698
Third Party AdvisoryVDB Entry
securitytracker.com / id/1034671
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2869-1
Third Party Advisory