Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
putty putty vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2019-9898
Potential recycling of random numbers used in cryptography exists within PuTTY prior to 0.71.
Putty Putty
Fedoraproject Fedora 28
Fedoraproject Fedora 29
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Opensuse Leap 15.0
Netapp Oncommand Unified Manager -
561
VMScore
CVE-2017-17131
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00; VP9660 V500R002C10 have an DoS vulnerability due to insufficient validation of the parameter when a putty comment key is loaded. ...
Huawei Dp300 Firmware V500r002c00
Huawei Rp200 Firmware V500r002c00
Huawei Rp200 Firmware V600r006c00
Huawei Te30 Firmware V100r001c10
Huawei Te30 Firmware V600r006c00
Huawei Te50 Firmware V600r006c00
Huawei Te60 Firmware V500r002c00
Huawei Te60 Firmware V100r001c10
Huawei Te60 Firmware V600r006c00
Huawei Vp9660 Firmware V500r002c10
755
VMScore
CVE-2017-6542
The ssh_agent_channel_data function in PuTTY prior to 0.68 allows remote malicious users to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, w...
Putty Putty
Opensuse Project Leap 42.1
Opensuse Leap 42.2
1 EDB exploit
392
VMScore
CVE-2016-6167
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll file in the current working directory.
Putty Putty 0.67
755
VMScore
CVE-2016-2563
Stack-based buffer overflow in the SCP command-line utility in PuTTY prior to 0.67 and KiTTY 0.66.6.3 and previous versions allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP d...
9bis Kitty
Simon Tatham Putty
1 EDB exploit
383
VMScore
CVE-2015-5309
Integer overflow in the terminal emulator in PuTTY prior to 0.66 allows remote malicious users to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which triggers a buffer u...
Opensuse Leap 42.1
Opensuse Opensuse 13.1
Opensuse Opensuse 13.2
Simon Tatham Putty
187
VMScore
CVE-2015-2157
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 up to and including 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
Fedoraproject Fedora 20
Fedoraproject Fedora 22
Debian Debian Linux 7.0
Opensuse Opensuse 13.1
Opensuse Opensuse 13.2
Putty Putty 0.54
Putty Putty 0.55
Putty Putty 0.62
Putty Putty 0.63
Putty Putty 0.51
Putty Putty 0.52
Putty Putty 0.58
Putty Putty 0.59
Putty Putty 0.56
Putty Putty 0.57
Simon Tatham Putty 0.53
Putty Putty 0.53b
Putty Putty 0.60
Putty Putty 0.61
187
VMScore
CVE-2011-4607
PuTTY 0.59 up to and including 0.61 does not clear sensitive process memory when managing user replies that occur during keyboard-interactive authentication, which might allow local users to read login passwords by obtaining access to the process' memory.
Putty Putty 0.61
Putty Putty 0.60
Putty Putty 0.59
383
VMScore
CVE-2013-4207
Buffer overflow in sshbn.c in PuTTY prior to 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not properly handled during computation of a modular inverse and triggers the overflow during a division by zero by the bignum fun...
Putty Putty 0.57
Putty Putty 0.56
Putty Putty 0.55
Putty Putty 0.54
Putty Putty 0.53b
Simon Tatham Putty
Putty Putty 0.49
Putty Putty 0.48
Putty Putty 0.47
Putty Putty 0.46
Putty Putty 0.60
Putty Putty 0.58
Putty Putty 0.52
Putty Putty 0.50
Putty Putty 0.45
Putty Putty 0.61
Putty Putty 0.59
Simon Tatham Putty 0.53
Putty Putty 0.51
Putty Putty 2010-06-01
187
VMScore
CVE-2013-4208
The rsa_verify function in PuTTY prior to 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.
Putty Putty 0.54
Putty Putty 0.53b
Simon Tatham Putty 0.53
Putty Putty 0.52
Putty Putty 0.61
Simon Tatham Putty
Putty Putty 0.60
Putty Putty 0.59
Putty Putty 0.47
Putty Putty 0.46
Putty Putty 0.45
Putty Putty 0.57
Putty Putty 0.55
Putty Putty 0.51
Putty Putty 0.49
Putty Putty 0.58
Putty Putty 0.56
Putty Putty 0.50
Putty Putty 0.48
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »