Vulnerabilities > 9Bis > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-09 | CVE-2024-23749 | Command Injection vulnerability in 9Bis Kitty KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). | 7.8 |
2024-02-09 | CVE-2024-25003 | Out-of-bounds Write vulnerability in 9Bis Kitty KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. | 7.8 |
2024-02-09 | CVE-2024-25004 | Out-of-bounds Write vulnerability in 9Bis Kitty KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). | 7.8 |