Celestial Software maintains a focused terminal emulation and remote-access product line centered on Absolute Telnet, which provides telnet and SSH connectivity for system administration and legacy infrastructure access. The observed vulnerability signal reflects application-level input and protocol-handling exposure typical of network client software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Celestial Software over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1090HIGH Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. | Feb 6, 2003 | 10.0 | 40 | NO | YES |
CVE-2021-47765MEDIUM AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can | Jan 15, 2026 | 5.5 | 23 | NO | NO |
CVE-2021-47764MEDIUM AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating DialUp connection and license name fields. Atta | Jan 15, 2026 | 5.5 | 23 | NO | NO |
CVE-2020-37166MEDIUM AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the u | Feb 7, 2026 | 5.5 | 20 | NO | NO |
CVE-2020-37165MEDIUM AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate | Feb 7, 2026 | 5.5 | 20 | NO | NO |
CVE-2020-37164MEDIUM AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate | Feb 7, 2026 | 5.5 | 20 | NO | NO |
CVE-2003-0046MEDIUM AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentia | Feb 19, 2003 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Celestial Software.
Media articles that mention a CVE ID that affects a product developed by Celestial Software — matched by CVE ID, not by vendor name.