Перейти к содержимому
Noroxi

Записи PuTTY

36 опубликованных записей вендора putty.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 2,8 %
Pre-auth RCE
9
С записью об исправлении
77,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

36 записей
  • CVE-2002-1359
    64На этой неделе

    Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial o

    КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %

    cisco · ios23 дек. 2002 г.

  • CVE-2023-48795
    51В плане

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    СредняяCVSS 5,9Proof of conceptEPSS 94 %

    ssh · ssh18 дек. 2023 г.

  • CVE-2017-6542
    46В плане

    The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a

    КритическаяCVSS 9,8Proof of conceptEPSS 22 %

    putty · putty27 мар. 2017 г.

  • CVE-2002-1357
    43В плане

    Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote a

    КритическаяCVSS 10,0Эксплойта нетEPSS 10 %

    cisco · ios23 дек. 2002 г.

  • CVE-2004-1008
    42В плане

    Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DE

    КритическаяCVSS 10,0Эксплойта нетEPSS 7 %

    putty · putty10 янв. 2005 г.

  • CVE-2002-1360
    42В плане

    Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengt

    КритическаяCVSS 10,0Эксплойта нетEPSS 6 %

    cisco · ios23 дек. 2002 г.

  • CVE-2002-1358
    42В плане

    Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a d

    КритическаяCVSS 10,0Эксплойта нетEPSS 6 %

    cisco · ios23 дек. 2002 г.

  • CVE-2019-9898
    40В плане

    Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    putty · putty21 мар. 2019 г.

  • CVE-2019-9895
    40В плане

    In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    putty · putty21 мар. 2019 г.

  • CVE-2019-17067
    39Наблюдать

    PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    putty · putty1 окт. 2019 г.

  • CVE-2021-36367
    32Наблюдать

    PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    putty · putty9 июл. 2021 г.

  • CVE-2004-1440
    31Наблюдать

    Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    putty · putty31 дек. 2004 г.

  • CVE-2005-0467
    31Наблюдать

    Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, an

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    putty · putty21 февр. 2005 г.

  • CVE-2019-9897
    31Наблюдать

    Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    putty · putty21 мар. 2019 г.

  • CVE-2019-9894
    31Наблюдать

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    putty · putty21 мар. 2019 г.

  • CVE-2019-17069
    31Наблюдать

    PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNE

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    putty · putty1 окт. 2019 г.

  • CVE-2003-0069
    31Наблюдать

    The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    putty · putty18 мар. 2003 г.

  • CVE-2021-33500
    31Наблюдать

    PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    putty · putty21 мая 2021 г.

  • CVE-2019-17068
    31Наблюдать

    PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboar

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    putty · putty1 окт. 2019 г.

  • CVE-2019-9896
    31Наблюдать

    In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same director

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    putty · putty21 мар. 2019 г.

  • CVE-2016-6167
    31Наблюдать

    Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking atta

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    putty · putty30 янв. 2017 г.

  • CVE-2013-4852
    28Наблюдать

    Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deni

    СредняяCVSS 6,8Эксплойта нетEPSS 3 %

    winscp · winscp19 авг. 2013 г.

  • CVE-2013-4206
    28Наблюдать

    Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (c

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    putty · putty19 авг. 2013 г.

  • CVE-2024-31497
    25Наблюдать

    In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui

    СредняяCVSS 5,9Proof of conceptEPSS 6 %

    putty · putty15 апр. 2024 г.

  • CVE-2020-14002
    24Наблюдать

    PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.

    СредняяCVSS 5,9Эксплойта нетEPSS 3 %

    putty · putty29 июн. 2020 г.