Vulnerabilities > Jcraft

DATE CVE VULNERABILITY TITLE RISK
2017-01-19 CVE-2016-5725 Path Traversal vulnerability in Jcraft Jsch
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
network
jcraft CWE-22
4.3
2002-12-31 CVE-2002-2102 Denial Of Service vulnerability in JZLib
InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data.
network
low complexity
jcraft
5.0