PuTTY kayıtları
putty üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,8
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-20 Improper Input Validation3
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-320 Key Management Errors1
- CWE-330 Use of Insufficiently Random Values1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2002-1359Silahlaştırılmış | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial ocisco · ios · CWE-20 | Kritik10,0 | — | %80,2 | 23 Ara 2002 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
46Planlayın | CVE-2017-6542Kavram kanıtı | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an aputty · putty · CWE-119 | Kritik9,8 | — | %21,8 | 27 Mar 2017 |
43Planlayın | CVE-2002-1357İstismar yok | Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote acisco · ios · CWE-119 | Kritik10,0 | — | %9,8 | 23 Ara 2002 |
42Planlayın | CVE-2004-1008İstismar yok | Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEputty · putty | Kritik10,0 | — | %7,4 | 10 Oca 2005 |
42Planlayın | CVE-2002-1360İstismar yok | Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengtcisco · ios · CWE-20 | Kritik10,0 | — | %6,1 | 23 Ara 2002 |
42Planlayın | CVE-2002-1358İstismar yok | Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a dcisco · ios · CWE-20 | Kritik10,0 | — | %5,8 | 23 Ara 2002 |
40Planlayın | CVE-2019-9898İstismar yok | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.putty · putty · CWE-330 | Kritik9,8 | — | %3,9 | 21 Mar 2019 |
40Planlayın | CVE-2019-9895İstismar yok | In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.putty · putty · CWE-119 | Kritik9,8 | — | %2,6 | 21 Mar 2019 |
39İzleyin | CVE-2019-17067İstismar yok | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal putty · putty · CWE-770 | Kritik9,8 | — | %1,6 | 1 Eki 2019 |
32İzleyin | CVE-2021-36367İstismar yok | PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.putty · putty · CWE-345 | Yüksek8,1 | — | %1,1 | 9 Tem 2021 |
31İzleyin | CVE-2004-1440İstismar yok | Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via anputty · putty | Yüksek7,5 | — | %4,1 | 31 Ara 2004 |
31İzleyin | CVE-2005-0467İstismar yok | Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, anputty · putty | Yüksek7,5 | — | %3,8 | 21 Şub 2005 |
31İzleyin | CVE-2019-9897İstismar yok | Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.putty · putty | Yüksek7,5 | — | %3,0 | 21 Mar 2019 |
31İzleyin | CVE-2019-9894İstismar yok | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.putty · putty · CWE-320 | Yüksek7,5 | — | %2,4 | 21 Mar 2019 |
31İzleyin | CVE-2019-17069İstismar yok | PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNEputty · putty · CWE-416 | Yüksek7,5 | — | %2,2 | 1 Eki 2019 |
31İzleyin | CVE-2003-0069İstismar yok | The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it backputty · putty | Yüksek7,5 | — | %2,2 | 18 Mar 2003 |
31İzleyin | CVE-2021-33500İstismar yok | PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change itsputty · putty | Yüksek7,5 | — | %2,0 | 21 May 2021 |
31İzleyin | CVE-2019-17068İstismar yok | PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboarputty · putty · CWE-74 | Yüksek7,5 | — | %1,8 | 1 Eki 2019 |
31İzleyin | CVE-2019-9896Kavram kanıtı | In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directorputty · putty · CWE-427 | Yüksek7,8 | — | %0,8 | 21 Mar 2019 |
31İzleyin | CVE-2016-6167İstismar yok | Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attaputty · putty · CWE-426 | Yüksek7,8 | — | %0,8 | 30 Oca 2017 |
28İzleyin | CVE-2013-4852İstismar yok | Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deniwinscp · winscp · CWE-189 | Orta6,8 | — | %3,4 | 19 Ağu 2013 |
28İzleyin | CVE-2013-4206İstismar yok | Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (cputty · putty · CWE-119 | Orta6,8 | — | %2,5 | 19 Ağu 2013 |
25İzleyin | CVE-2024-31497Kavram kanıtı | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quiputty · putty · CWE-338 | Orta5,9 | — | %5,8 | 15 Nis 2024 |
24İzleyin | CVE-2020-14002İstismar yok | PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.putty · putty · CWE-203 | Orta5,9 | — | %3,1 | 29 Haz 2020 |
- CVE-2002-135964Bu hafta
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial o
KritikCVSS 10,0SilahlaştırılmışEPSS %80cisco · ios23 Ara 2002
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2017-654246Planlayın
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a
KritikCVSS 9,8Kavram kanıtıEPSS %22putty · putty27 Mar 2017
- CVE-2002-135743Planlayın
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote a
KritikCVSS 10,0İstismar yokEPSS %10cisco · ios23 Ara 2002
- CVE-2004-100842Planlayın
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DE
KritikCVSS 10,0İstismar yokEPSS %7putty · putty10 Oca 2005
- CVE-2002-136042Planlayın
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengt
KritikCVSS 10,0İstismar yokEPSS %6cisco · ios23 Ara 2002
- CVE-2002-135842Planlayın
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a d
KritikCVSS 10,0İstismar yokEPSS %6cisco · ios23 Ara 2002
- CVE-2019-989840Planlayın
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
KritikCVSS 9,8İstismar yokEPSS %4putty · putty21 Mar 2019
- CVE-2019-989540Planlayın
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
KritikCVSS 9,8İstismar yokEPSS %3putty · putty21 Mar 2019
- CVE-2019-1706739İzleyin
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal
KritikCVSS 9,8İstismar yokEPSS %2putty · putty1 Eki 2019
- CVE-2021-3636732İzleyin
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.
YüksekCVSS 8,1İstismar yokEPSS %1putty · putty9 Tem 2021
- CVE-2004-144031İzleyin
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an
YüksekCVSS 7,5İstismar yokEPSS %4putty · putty31 Ara 2004
- CVE-2005-046731İzleyin
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, an
YüksekCVSS 7,5İstismar yokEPSS %4putty · putty21 Şub 2005
- CVE-2019-989731İzleyin
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
YüksekCVSS 7,5İstismar yokEPSS %3putty · putty21 Mar 2019
- CVE-2019-989431İzleyin
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
YüksekCVSS 7,5İstismar yokEPSS %2putty · putty21 Mar 2019
- CVE-2019-1706931İzleyin
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNE
YüksekCVSS 7,5İstismar yokEPSS %2putty · putty1 Eki 2019
- CVE-2003-006931İzleyin
The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back
YüksekCVSS 7,5İstismar yokEPSS %2putty · putty18 Mar 2003
- CVE-2021-3350031İzleyin
PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its
YüksekCVSS 7,5İstismar yokEPSS %2putty · putty21 May 2021
- CVE-2019-1706831İzleyin
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboar
YüksekCVSS 7,5İstismar yokEPSS %2putty · putty1 Eki 2019
- CVE-2019-989631İzleyin
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same director
YüksekCVSS 7,8Kavram kanıtıEPSS %1putty · putty21 Mar 2019
- CVE-2016-616731İzleyin
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking atta
YüksekCVSS 7,8İstismar yokEPSS %1putty · putty30 Oca 2017
- CVE-2013-485228İzleyin
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deni
OrtaCVSS 6,8İstismar yokEPSS %3winscp · winscp19 Ağu 2013
- CVE-2013-420628İzleyin
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (c
OrtaCVSS 6,8İstismar yokEPSS %2putty · putty19 Ağu 2013
- CVE-2024-3149725İzleyin
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui
OrtaCVSS 5,9Kavram kanıtıEPSS %6putty · putty15 Nis 2024
- CVE-2020-1400224İzleyin
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.
OrtaCVSS 5,9İstismar yokEPSS %3putty · putty29 Haz 2020