Home/Product/winscp
Product

winscp

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-31497
< 6.3.3
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key
5.9MEDIUM
CVE-2023-48795
< 6.2.2
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9MEDIUM
CVE-2021-3331
< 5.17.10
WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loa
9.8CRITICAL
CVE-2020-28864
all versions
Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspecified imp
9.8CRITICAL
CVE-2019-6111
<= 5.1.3
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/
5.9MEDIUM
CVE-2019-6110
<= 5.13
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle
6.8MEDIUM
CVE-2019-6109
<= 5.13
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-T
6.8MEDIUM
CVE-2018-20685
<= 5.13
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or
5.3MEDIUM
CVE-2018-20684
<= 5.13.7
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, pot
7.5HIGH
CVE-2014-2735
<= 5.5.2
WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the subject's Co
CVE-2013-4852
<= 5.1.5
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to ca
CVE-2007-4909
all versions
Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server vi
CVE-2006-3015
all versions
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encod
CVE-2002-1360
all versions
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified
CVE-2002-1359
all versions
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause
CVE-2002-1358
all versions
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to
CVE-2002-1357
all versions
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allo
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin