İçeriğe atla
Noroxi

PuTTY kayıtları

putty üreticisine ait 36 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %2,8
Pre-auth RCE
9
Düzeltme kaydı olan
%77,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

36 kayıt
  • CVE-2002-1359
    64Bu hafta

    Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial o

    KritikCVSS 10,0SilahlaştırılmışEPSS %80

    cisco · ios23 Ara 2002

  • CVE-2023-48795
    51Planlayın

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    OrtaCVSS 5,9Kavram kanıtıEPSS %94

    ssh · ssh18 Ara 2023

  • CVE-2017-6542
    46Planlayın

    The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a

    KritikCVSS 9,8Kavram kanıtıEPSS %22

    putty · putty27 Mar 2017

  • CVE-2002-1357
    43Planlayın

    Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote a

    KritikCVSS 10,0İstismar yokEPSS %10

    cisco · ios23 Ara 2002

  • CVE-2004-1008
    42Planlayın

    Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DE

    KritikCVSS 10,0İstismar yokEPSS %7

    putty · putty10 Oca 2005

  • CVE-2002-1360
    42Planlayın

    Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a lengt

    KritikCVSS 10,0İstismar yokEPSS %6

    cisco · ios23 Ara 2002

  • CVE-2002-1358
    42Planlayın

    Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a d

    KritikCVSS 10,0İstismar yokEPSS %6

    cisco · ios23 Ara 2002

  • CVE-2019-9898
    40Planlayın

    Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

    KritikCVSS 9,8İstismar yokEPSS %4

    putty · putty21 Mar 2019

  • CVE-2019-9895
    40Planlayın

    In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

    KritikCVSS 9,8İstismar yokEPSS %3

    putty · putty21 Mar 2019

  • CVE-2019-17067
    39İzleyin

    PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal

    KritikCVSS 9,8İstismar yokEPSS %2

    putty · putty1 Eki 2019

  • CVE-2021-36367
    32İzleyin

    PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.

    YüksekCVSS 8,1İstismar yokEPSS %1

    putty · putty9 Tem 2021

  • CVE-2004-1440
    31İzleyin

    Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an

    YüksekCVSS 7,5İstismar yokEPSS %4

    putty · putty31 Ara 2004

  • CVE-2005-0467
    31İzleyin

    Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, an

    YüksekCVSS 7,5İstismar yokEPSS %4

    putty · putty21 Şub 2005

  • CVE-2019-9897
    31İzleyin

    Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.

    YüksekCVSS 7,5İstismar yokEPSS %3

    putty · putty21 Mar 2019

  • CVE-2019-9894
    31İzleyin

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

    YüksekCVSS 7,5İstismar yokEPSS %2

    putty · putty21 Mar 2019

  • CVE-2019-17069
    31İzleyin

    PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNE

    YüksekCVSS 7,5İstismar yokEPSS %2

    putty · putty1 Eki 2019

  • CVE-2003-0069
    31İzleyin

    The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back

    YüksekCVSS 7,5İstismar yokEPSS %2

    putty · putty18 Mar 2003

  • CVE-2021-33500
    31İzleyin

    PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its

    YüksekCVSS 7,5İstismar yokEPSS %2

    putty · putty21 May 2021

  • CVE-2019-17068
    31İzleyin

    PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboar

    YüksekCVSS 7,5İstismar yokEPSS %2

    putty · putty1 Eki 2019

  • CVE-2019-9896
    31İzleyin

    In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same director

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    putty · putty21 Mar 2019

  • CVE-2016-6167
    31İzleyin

    Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking atta

    YüksekCVSS 7,8İstismar yokEPSS %1

    putty · putty30 Oca 2017

  • CVE-2013-4852
    28İzleyin

    Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a deni

    OrtaCVSS 6,8İstismar yokEPSS %3

    winscp · winscp19 Ağu 2013

  • CVE-2013-4206
    28İzleyin

    Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (c

    OrtaCVSS 6,8İstismar yokEPSS %2

    putty · putty19 Ağu 2013

  • CVE-2024-31497
    25İzleyin

    In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui

    OrtaCVSS 5,9Kavram kanıtıEPSS %6

    putty · putty15 Nis 2024

  • CVE-2020-14002
    24İzleyin

    PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation.

    OrtaCVSS 5,9İstismar yokEPSS %3

    putty · putty29 Haz 2020