Securecrt
Vendor:
First CVE: Dec 30, 2001 · Active for 24 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Securecrt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2001
24 years ago
Most Recent CVE
Mar 7, 2006
7,448 days ago
CVE Severity & Scoring
Securecrt5 CVEs
20%
80%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1059HIGH Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string. | Oct 4, 2002 | 7.5 | 70 | NO | YES |
CVE-2006-1038HIGH Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" str | Mar 7, 2006 | 10.0 | 25 | NO | NO |
CVE-2004-1541HIGH SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file o | Dec 31, 2004 | 7.5 | 24 | NO | NO |
CVE-2001-1466HIGH Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password. | Dec 30, 2001 | 7.5 | 20 | NO | NO |
CVE-2003-0047MEDIUM SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plai | Feb 19, 2003 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
20.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Securecrt
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0_beta_6 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0_beta_5 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0_beta_4 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0_beta_3 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0_beta_2 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0_beta_1 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0.4 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0.3 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0.2 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0.1 | 1 | 10.0 | 3.1% | 0 | 0 |
| 5.0 | 1 | 10.0 | 3.1% | 0 | 0 |
| 4.1.8 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.7 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.6 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.5 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.4 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.3 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.2 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1.1 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.1 | 1 | 7.5 | 2.1% | 0 | 0 |