Записи PuTTY
36 опубликованных записей вендора putty.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,8 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 77,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-20 Improper Input Validation3
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-320 Key Management Errors1
- CWE-330 Use of Insufficiently Random Values1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2002-1359Готовый эксплойт | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial ocisco · ios · CWE-20 | Критическая10,0 | — | 80,2 % | 23 дек. 2002 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
46В плане | CVE-2017-6542Proof of concept | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an aputty · putty · CWE-119 | Критическая9,8 | — | 21,8 % | 27 мар. 2017 г. |
43В плане | CVE-2002-1357Эксплойта нет | Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote acisco · ios · CWE-119 | Критическая10,0 | — | 9,8 % | 23 дек. 2002 г. |
42В плане | CVE-2004-1008Эксплойта нет | Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEputty · putty | Критическая10,0 | — | 7,4 % | 10 янв. 2005 г. |
42В плане | CVE-2002-1360Эксплойта нет | Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengtcisco · ios · CWE-20 | Критическая10,0 | — | 6,1 % | 23 дек. 2002 г. |
42В плане | CVE-2002-1358Эксплойта нет | Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a dcisco · ios · CWE-20 | Критическая10,0 | — | 5,8 % | 23 дек. 2002 г. |
40В плане | CVE-2019-9898Эксплойта нет | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.putty · putty · CWE-330 | Критическая9,8 | — | 3,9 % | 21 мар. 2019 г. |
40В плане | CVE-2019-9895Эксплойта нет | In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.putty · putty · CWE-119 | Критическая9,8 | — | 2,6 % | 21 мар. 2019 г. |
39Наблюдать | CVE-2019-17067Эксплойта нет | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal putty · putty · CWE-770 | Критическая9,8 | — | 1,6 % | 1 окт. 2019 г. |
32Наблюдать | CVE-2021-36367Эксплойта нет | PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.putty · putty · CWE-345 | Высокая8,1 | — | 1,1 % | 9 июл. 2021 г. |
31Наблюдать | CVE-2004-1440Эксплойта нет | Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via anputty · putty | Высокая7,5 | — | 4,1 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2005-0467Эксплойта нет | Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, anputty · putty | Высокая7,5 | — | 3,8 % | 21 февр. 2005 г. |
31Наблюдать | CVE-2019-9897Эксплойта нет | Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.putty · putty | Высокая7,5 | — | 3,0 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2019-9894Эксплойта нет | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.putty · putty · CWE-320 | Высокая7,5 | — | 2,4 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2019-17069Эксплойта нет | PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNEputty · putty · CWE-416 | Высокая7,5 | — | 2,2 % | 1 окт. 2019 г. |
31Наблюдать | CVE-2003-0069Эксплойта нет | The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it backputty · putty | Высокая7,5 | — | 2,2 % | 18 мар. 2003 г. |
31Наблюдать | CVE-2021-33500Эксплойта нет | PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change itsputty · putty | Высокая7,5 | — | 2,0 % | 21 мая 2021 г. |
31Наблюдать | CVE-2019-17068Эксплойта нет | PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboarputty · putty · CWE-74 | Высокая7,5 | — | 1,8 % | 1 окт. 2019 г. |
31Наблюдать | CVE-2019-9896Proof of concept | In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directorputty · putty · CWE-427 | Высокая7,8 | — | 0,8 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2016-6167Эксплойта нет | Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attaputty · putty · CWE-426 | Высокая7,8 | — | 0,8 % | 30 янв. 2017 г. |
28Наблюдать | CVE-2013-4852Эксплойта нет | Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deniwinscp · winscp · CWE-189 | Средняя6,8 | — | 3,4 % | 19 авг. 2013 г. |
28Наблюдать | CVE-2013-4206Эксплойта нет | Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (cputty · putty · CWE-119 | Средняя6,8 | — | 2,5 % | 19 авг. 2013 г. |
25Наблюдать | CVE-2024-31497Proof of concept | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quiputty · putty · CWE-338 | Средняя5,9 | — | 5,8 % | 15 апр. 2024 г. |
24Наблюдать | CVE-2020-14002Эксплойта нет | PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.putty · putty · CWE-203 | Средняя5,9 | — | 3,1 % | 29 июн. 2020 г. |
- CVE-2002-135964На этой неделе
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial o
КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %cisco · ios23 дек. 2002 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2017-654246В плане
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a
КритическаяCVSS 9,8Proof of conceptEPSS 22 %putty · putty27 мар. 2017 г.
- CVE-2002-135743В плане
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote a
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %cisco · ios23 дек. 2002 г.
- CVE-2004-100842В плане
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DE
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %putty · putty10 янв. 2005 г.
- CVE-2002-136042В плане
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengt
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %cisco · ios23 дек. 2002 г.
- CVE-2002-135842В плане
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a d
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %cisco · ios23 дек. 2002 г.
- CVE-2019-989840В плане
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %putty · putty21 мар. 2019 г.
- CVE-2019-989540В плане
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %putty · putty21 мар. 2019 г.
- CVE-2019-1706739Наблюдать
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %putty · putty1 окт. 2019 г.
- CVE-2021-3636732Наблюдать
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %putty · putty9 июл. 2021 г.
- CVE-2004-144031Наблюдать
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %putty · putty31 дек. 2004 г.
- CVE-2005-046731Наблюдать
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, an
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %putty · putty21 февр. 2005 г.
- CVE-2019-989731Наблюдать
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %putty · putty21 мар. 2019 г.
- CVE-2019-989431Наблюдать
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %putty · putty21 мар. 2019 г.
- CVE-2019-1706931Наблюдать
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNE
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %putty · putty1 окт. 2019 г.
- CVE-2003-006931Наблюдать
The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %putty · putty18 мар. 2003 г.
- CVE-2021-3350031Наблюдать
PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %putty · putty21 мая 2021 г.
- CVE-2019-1706831Наблюдать
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboar
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %putty · putty1 окт. 2019 г.
- CVE-2019-989631Наблюдать
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same director
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %putty · putty21 мар. 2019 г.
- CVE-2016-616731Наблюдать
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking atta
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %putty · putty30 янв. 2017 г.
- CVE-2013-485228Наблюдать
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deni
СредняяCVSS 6,8Эксплойта нетEPSS 3 %winscp · winscp19 авг. 2013 г.
- CVE-2013-420628Наблюдать
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (c
СредняяCVSS 6,8Эксплойта нетEPSS 2 %putty · putty19 авг. 2013 г.
- CVE-2024-3149725Наблюдать
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui
СредняяCVSS 5,9Proof of conceptEPSS 6 %putty · putty15 апр. 2024 г.
- CVE-2020-1400224Наблюдать
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %putty · putty29 июн. 2020 г.