PuTTY records
36 published records for vendor putty.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.8%
- Pre-auth RCE
- 9
- With a fix record
- 77.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-20 Improper Input Validation3
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-320 Key Management Errors1
- CWE-330 Use of Insufficiently Random Values1
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2002-1359Weaponized | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial ocisco · ios · CWE-20 | Critical10.0 | — | 80.2% | Dec 23, 2002 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
46Plan | CVE-2017-6542Proof of concept | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an aputty · putty · CWE-119 | Critical9.8 | — | 21.8% | Mar 27, 2017 |
43Plan | CVE-2002-1357No exploit | Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote acisco · ios · CWE-119 | Critical10.0 | — | 9.8% | Dec 23, 2002 |
42Plan | CVE-2004-1008No exploit | Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEputty · putty | Critical10.0 | — | 7.4% | Jan 10, 2005 |
42Plan | CVE-2002-1360No exploit | Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengtcisco · ios · CWE-20 | Critical10.0 | — | 6.1% | Dec 23, 2002 |
42Plan | CVE-2002-1358No exploit | Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a dcisco · ios · CWE-20 | Critical10.0 | — | 5.8% | Dec 23, 2002 |
40Plan | CVE-2019-9898No exploit | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.putty · putty · CWE-330 | Critical9.8 | — | 3.9% | Mar 21, 2019 |
40Plan | CVE-2019-9895No exploit | In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.putty · putty · CWE-119 | Critical9.8 | — | 2.6% | Mar 21, 2019 |
39Monitor | CVE-2019-17067No exploit | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal putty · putty · CWE-770 | Critical9.8 | — | 1.6% | Oct 1, 2019 |
32Monitor | CVE-2021-36367No exploit | PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.putty · putty · CWE-345 | High8.1 | — | 1.1% | Jul 9, 2021 |
31Monitor | CVE-2004-1440No exploit | Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via anputty · putty | High7.5 | — | 4.1% | Dec 31, 2004 |
31Monitor | CVE-2005-0467No exploit | Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, anputty · putty | High7.5 | — | 3.8% | Feb 21, 2005 |
31Monitor | CVE-2019-9897No exploit | Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.putty · putty | High7.5 | — | 3.0% | Mar 21, 2019 |
31Monitor | CVE-2019-9894No exploit | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.putty · putty · CWE-320 | High7.5 | — | 2.4% | Mar 21, 2019 |
31Monitor | CVE-2019-17069No exploit | PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNEputty · putty · CWE-416 | High7.5 | — | 2.2% | Oct 1, 2019 |
31Monitor | CVE-2003-0069No exploit | The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it backputty · putty | High7.5 | — | 2.2% | Mar 18, 2003 |
31Monitor | CVE-2021-33500No exploit | PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change itsputty · putty | High7.5 | — | 2.0% | May 21, 2021 |
31Monitor | CVE-2019-17068No exploit | PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboarputty · putty · CWE-74 | High7.5 | — | 1.8% | Oct 1, 2019 |
31Monitor | CVE-2019-9896Proof of concept | In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directorputty · putty · CWE-427 | High7.8 | — | 0.8% | Mar 21, 2019 |
31Monitor | CVE-2016-6167No exploit | Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attaputty · putty · CWE-426 | High7.8 | — | 0.8% | Jan 30, 2017 |
28Monitor | CVE-2013-4852No exploit | Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deniwinscp · winscp · CWE-189 | Medium6.8 | — | 3.4% | Aug 19, 2013 |
28Monitor | CVE-2013-4206No exploit | Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (cputty · putty · CWE-119 | Medium6.8 | — | 2.5% | Aug 19, 2013 |
25Monitor | CVE-2024-31497Proof of concept | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quiputty · putty · CWE-338 | Medium5.9 | — | 5.8% | Apr 15, 2024 |
24Monitor | CVE-2020-14002No exploit | PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.putty · putty · CWE-203 | Medium5.9 | — | 3.1% | Jun 29, 2020 |
- CVE-2002-135964This week
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial o
CriticalCVSS 10.0WeaponizedEPSS 80%cisco · iosDec 23, 2002
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2017-654246Plan
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a
CriticalCVSS 9.8Proof of conceptEPSS 22%putty · puttyMar 27, 2017
- CVE-2002-135743Plan
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote a
CriticalCVSS 10.0No exploitEPSS 10%cisco · iosDec 23, 2002
- CVE-2004-100842Plan
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DE
CriticalCVSS 10.0No exploitEPSS 7%putty · puttyJan 10, 2005
- CVE-2002-136042Plan
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengt
CriticalCVSS 10.0No exploitEPSS 6%cisco · iosDec 23, 2002
- CVE-2002-135842Plan
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a d
CriticalCVSS 10.0No exploitEPSS 6%cisco · iosDec 23, 2002
- CVE-2019-989840Plan
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
CriticalCVSS 9.8No exploitEPSS 4%putty · puttyMar 21, 2019
- CVE-2019-989540Plan
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
CriticalCVSS 9.8No exploitEPSS 3%putty · puttyMar 21, 2019
- CVE-2019-1706739Monitor
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal
CriticalCVSS 9.8No exploitEPSS 2%putty · puttyOct 1, 2019
- CVE-2021-3636732Monitor
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.
HighCVSS 8.1No exploitEPSS 1%putty · puttyJul 9, 2021
- CVE-2004-144031Monitor
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an
HighCVSS 7.5No exploitEPSS 4%putty · puttyDec 31, 2004
- CVE-2005-046731Monitor
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, an
HighCVSS 7.5No exploitEPSS 4%putty · puttyFeb 21, 2005
- CVE-2019-989731Monitor
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
HighCVSS 7.5No exploitEPSS 3%putty · puttyMar 21, 2019
- CVE-2019-989431Monitor
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
HighCVSS 7.5No exploitEPSS 2%putty · puttyMar 21, 2019
- CVE-2019-1706931Monitor
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNE
HighCVSS 7.5No exploitEPSS 2%putty · puttyOct 1, 2019
- CVE-2003-006931Monitor
The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back
HighCVSS 7.5No exploitEPSS 2%putty · puttyMar 18, 2003
- CVE-2021-3350031Monitor
PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its
HighCVSS 7.5No exploitEPSS 2%putty · puttyMay 21, 2021
- CVE-2019-1706831Monitor
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboar
HighCVSS 7.5No exploitEPSS 2%putty · puttyOct 1, 2019
- CVE-2019-989631Monitor
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same director
HighCVSS 7.8Proof of conceptEPSS 1%putty · puttyMar 21, 2019
- CVE-2016-616731Monitor
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking atta
HighCVSS 7.8No exploitEPSS 1%putty · puttyJan 30, 2017
- CVE-2013-485228Monitor
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deni
MediumCVSS 6.8No exploitEPSS 3%winscp · winscpAug 19, 2013
- CVE-2013-420628Monitor
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (c
MediumCVSS 6.8No exploitEPSS 2%putty · puttyAug 19, 2013
- CVE-2024-3149725Monitor
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui
MediumCVSS 5.9Proof of conceptEPSS 6%putty · puttyApr 15, 2024
- CVE-2020-1400224Monitor
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.
MediumCVSS 5.9No exploitEPSS 3%putty · puttyJun 29, 2020