9bis records
5 published records for vendor 9bis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
49Plan | CVE-2016-2563Proof of concept | Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cau9bis · kitty · CWE-119 | Critical9.8 | — | 34.2% | Apr 7, 2016 |
32Monitor | CVE-2024-23749Proof of concept | KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitizat9bis · kitty · CWE-77 | High7.8 | — | 4.7% | Feb 9, 2024 |
32Monitor | CVE-2024-25003Proof of concept | KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds check9bis · kitty · CWE-787 | High7.8 | — | 1.8% | Feb 9, 2024 |
32Monitor | CVE-2024-25004Proof of concept | KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds check9bis · kitty · CWE-787 | High7.8 | — | 1.8% | Feb 9, 2024 |
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2016-256349Plan
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cau
CriticalCVSS 9.8Proof of conceptEPSS 34%9bis · kittyApr 7, 2016
- CVE-2024-2374932Monitor
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitizat
HighCVSS 7.8Proof of conceptEPSS 5%9bis · kittyFeb 9, 2024
- CVE-2024-2500332Monitor
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds check
HighCVSS 7.8Proof of conceptEPSS 2%9bis · kittyFeb 9, 2024
- CVE-2024-2500432Monitor
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds check
HighCVSS 7.8Proof of conceptEPSS 2%9bis · kittyFeb 9, 2024