PuTTY is a widely used SSH and Telnet client whose vulnerability footprint, while concentrated in a single product, carries disproportionate impact due to its ubiquity in system administration and remote-access workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the sensitivity of credential handling and protocol implementation in a client that sits at the boundary between user systems and backend infrastructure. The recurring weakness classes center on memory-safety issues such as buffer-boundary violations and out-of-bounds access, alongside input-validation and information-disclosure flaws that are characteristic of native C implementations handling untrusted network data. Defenders should prioritize PuTTY updates in environments where it manages access to sensitive systems, and should treat the client as part of the baseline hygiene for administrative workstations. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Putty over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1359HIGH Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary | Dec 23, 2002 | 10.0 | 85 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2017-6542CRITICAL The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the | Mar 27, 2017 | 9.8 | 54 | NO | YES |
CVE-2002-1357HIGH Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or | Dec 23, 2002 | 10.0 | 35 | NO | NO |
CVE-2002-1358HIGH Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arb | Dec 23, 2002 | 10.0 | 33 | NO | NO |
CVE-2019-17067CRITICAL PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection. | Oct 1, 2019 | 9.8 | 31 | NO | NO |
CVE-2004-1008HIGH Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen par | Jan 10, 2005 | 10.0 | 29 | NO | NO |
CVE-2002-1360HIGH Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attack | Dec 23, 2002 | 10.0 | 29 | NO | NO |
CVE-2016-6167HIGH Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll o | Jan 30, 2017 | 7.8 | 26 | NO | NO |
CVE-2004-1440HIGH Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that i | Dec 31, 2004 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Putty.
Media articles that mention a CVE ID that affects a product developed by Putty — matched by CVE ID, not by vendor name.