Skip to content
Noroxi

PuTTY records

36 published records for vendor putty.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 2.8%
Pre-auth RCE
9
With a fix record
77.8%
Median publish → KEV
No record has entered KEV

All records

36 records
  • CVE-2002-1359
    64This week

    Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial o

    CriticalCVSS 10.0WeaponizedEPSS 80%

    cisco · iosDec 23, 2002

  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 94%

    ssh · sshDec 18, 2023

  • The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a

    CriticalCVSS 9.8Proof of conceptEPSS 22%

    putty · puttyMar 27, 2017

  • Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote a

    CriticalCVSS 10.0No exploitEPSS 10%

    cisco · iosDec 23, 2002

  • Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DE

    CriticalCVSS 10.0No exploitEPSS 7%

    putty · puttyJan 10, 2005

  • Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengt

    CriticalCVSS 10.0No exploitEPSS 6%

    cisco · iosDec 23, 2002

  • Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a d

    CriticalCVSS 10.0No exploitEPSS 6%

    cisco · iosDec 23, 2002

  • Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

    CriticalCVSS 9.8No exploitEPSS 4%

    putty · puttyMar 21, 2019

  • In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

    CriticalCVSS 9.8No exploitEPSS 3%

    putty · puttyMar 21, 2019

  • PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal

    CriticalCVSS 9.8No exploitEPSS 2%

    putty · puttyOct 1, 2019

  • PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.

    HighCVSS 8.1No exploitEPSS 1%

    putty · puttyJul 9, 2021

  • CVE-2004-1440
    31Monitor

    Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an

    HighCVSS 7.5No exploitEPSS 4%

    putty · puttyDec 31, 2004

  • CVE-2005-0467
    31Monitor

    Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, an

    HighCVSS 7.5No exploitEPSS 4%

    putty · puttyFeb 21, 2005

  • CVE-2019-9897
    31Monitor

    Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.

    HighCVSS 7.5No exploitEPSS 3%

    putty · puttyMar 21, 2019

  • CVE-2019-9894
    31Monitor

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

    HighCVSS 7.5No exploitEPSS 2%

    putty · puttyMar 21, 2019

  • PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNE

    HighCVSS 7.5No exploitEPSS 2%

    putty · puttyOct 1, 2019

  • CVE-2003-0069
    31Monitor

    The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back

    HighCVSS 7.5No exploitEPSS 2%

    putty · puttyMar 18, 2003

  • PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its

    HighCVSS 7.5No exploitEPSS 2%

    putty · puttyMay 21, 2021

  • PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboar

    HighCVSS 7.5No exploitEPSS 2%

    putty · puttyOct 1, 2019

  • CVE-2019-9896
    31Monitor

    In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same director

    HighCVSS 7.8Proof of conceptEPSS 1%

    putty · puttyMar 21, 2019

  • CVE-2016-6167
    31Monitor

    Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking atta

    HighCVSS 7.8No exploitEPSS 1%

    putty · puttyJan 30, 2017

  • CVE-2013-4852
    28Monitor

    Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deni

    MediumCVSS 6.8No exploitEPSS 3%

    winscp · winscpAug 19, 2013

  • CVE-2013-4206
    28Monitor

    Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (c

    MediumCVSS 6.8No exploitEPSS 2%

    putty · puttyAug 19, 2013

  • In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui

    MediumCVSS 5.9Proof of conceptEPSS 6%

    putty · puttyApr 15, 2024

  • PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.

    MediumCVSS 5.9No exploitEPSS 3%

    putty · puttyJun 29, 2020