Schollz maintains a focused file-transfer utility, croc, that enables secure point-to-point data sharing across networks. The vulnerability profile centers on information-disclosure and path-handling weaknesses, including exposure of sensitive data, path traversal, and output-encoding issues that are characteristic of tools handling user-supplied input and filesystem operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schollz over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43620HIGH An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver. | Sep 20, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-43619HIGH An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_keys file. | Sep 20, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-43621MEDIUM An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users who list all processes and their arguments. | Sep 20, 2023 | 4.7 | 18 | NO | NO |
CVE-2023-43618MEDIUM An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message. | Sep 20, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-43617MEDIUM An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of compo | Sep 20, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-43616MEDIUM An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction. | Sep 20, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schollz.
Media articles that mention a CVE ID that affects a product developed by Schollz — matched by CVE ID, not by vendor name.