Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Putty

First CVE: Jun 1, 2000Active for: 26 yearsTotal CVEs: 36
51.0
VTI Score
TOP TARGET

PuTTY is a widely used SSH and Telnet client whose vulnerability footprint, while concentrated in a single product, carries disproportionate impact due to its ubiquity in system administration and remote-access workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the sensitivity of credential handling and protocol implementation in a client that sits at the boundary between user systems and backend infrastructure. The recurring weakness classes center on memory-safety issues such as buffer-boundary violations and out-of-bounds access, alongside input-validation and information-disclosure flaws that are characteristic of native C implementations handling untrusted network data. Defenders should prioritize PuTTY updates in environments where it manages access to sensitive systems, and should treat the client as part of the baseline hygiene for administrative workstations. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Putty over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2000
26 years ago
Most Recent CVE
May 25, 2026
60 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-1359HIGH
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary
Dec 23, 200210.085NOYES
CVE-2023-48795MEDIUM
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
CVE-2017-6542CRITICAL
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the
Mar 27, 20179.854NOYES
CVE-2002-1357HIGH
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or
Dec 23, 200210.035NONO
CVE-2002-1358HIGH
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arb
Dec 23, 200210.033NONO
CVE-2019-17067CRITICAL
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.
Oct 1, 20199.831NONO
CVE-2004-1008HIGH
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen par
Jan 10, 200510.029NONO
CVE-2002-1360HIGH
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attack
Dec 23, 200210.029NONO
CVE-2016-6167HIGH
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll o
Jan 30, 20177.826NONO
CVE-2004-1440HIGH
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that i
Dec 31, 20047.526NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
19%
25%
44%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (5.6%)
Network17 (47.2%)
Unknown17 (47.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (33.3%)
High7 (19.4%)
Unknown17 (47.2%)
User Interaction
None16 (44.4%)
Unknown17 (47.2%)
Required3 (8.3%)
Privileges Required
Low1 (2.8%)
High0 (0.0%)
None18 (50.0%)
Unknown17 (47.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.8% of CVEs· 98th percentile
Nuclei
1 CVE
2.8% of CVEs· 95th percentile
ExploitDB
3 CVEs
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Putty.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Putty — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Putty's Products

View all 3 CNAs →

Top CWEs