Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Putty MEDIUM 5.9
CVE-2026-48850

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Fix: 0.84+
Fix from $1,600 2026-05-25
Putty HIGH 8.1
CVE-2021-36367

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier fo…

Fix: after 0.75
Fix from $1,950 2021-07-09
Putty HIGH 7.5
CVE-2021-33500

PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title re…

Fix: 0.75+
Fix from $1,950 2021-05-21
Putty CRITICAL 9.8
CVE-2019-17067

PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incomi…

Fix: 0.73+
Fix from $2,300 2019-10-01
Putty HIGH 7.5
CVE-2019-17068

PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.

Fix: 0.73+
Fix from $1,950 2019-10-01
Putty HIGH 7.5
CVE-2019-17069

PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT messag…

Fix: 0.73+
Fix from $1,950 2019-10-01
Putty HIGH 7.8
CVE-2019-9896

In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the …

Fix: 0.71+
Fix from $1,950 2019-03-21
Putty CRITICAL 9.8
CVE-2017-6542EPSS 22%

The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent prot…

Fix: after 0.67
Fix from $2,300 2017-03-27
Putty HIGH 7.8
CVE-2016-6167

Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a…

No fix yet
Fix from $1,950 2017-01-30
Putty MEDIUM 6.8
CVE-2013-4206

Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and…

Fix: after 0.62
Fix from $1,600 2013-08-19
Putty HIGH 7.5
CVE-2005-0467

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibl…

Fix: after 0.56
Fix from $1,950 2005-02-21
Putty HIGH 10.0
CVE-2004-1008EPSS 7%

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packe…

Patch available
Fix from $1,950 2005-01-10
Putty HIGH 7.5
CVE-2004-1440

Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 pac…

Patch available
Fix from $1,950 2004-12-31
Putty HIGH 7.5
CVE-2003-0069

The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the c…

Mitigation only
Fix from $1,950 2003-03-18