CVE Feed

    Dashboard / CVE / CVE-2016-2563

    CVE-2016-2563

    Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.

    Published:Apr 7, 2016
    Last Modified:Apr 12, 2025
    EPS:Apr 7, 2016
    EPSS Score:0.28635
    CVSS Score:9.8

    Affected Products

    Vendor
    9bis
    Product
    Kitty
    Vendor
    Simon Tatham
    Product
    Putty

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High