Celestialsoftware Absolutetelnet vulnerabilities
5 known vulnerabilities affecting celestialsoftware/absolutetelnet.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2021-47764P4MEDIUMCVSS 5.5v11.242026-01-15
CVE-2021-47764 [MEDIUM] CWE-787 CVE-2021-47764: AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash
AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating DialUp connection and license name fields. Attackers can generate a 1000-character payload and paste it into specific input fields to trigger application crashes and force unexpected termination.
nvd
CVE-2020-37166P4MEDIUMCVSS 5.5v11.122026-02-07
CVE-2020-37166 [MEDIUM] CWE-120 CVE-2020-37166: AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field tha
AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with a 1000-byte buffer, causing the application to become unresponsive and terminate.
nvd
CVE-2021-47765P4MEDIUMCVSS 5.5v11.242026-01-15
CVE-2021-47765 [MEDIUM] CWE-787 CVE-2021-47765: AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash
AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the username or email address fields, causing the application to become unresponsive.
nvd
CVE-2020-37164P4MEDIUMCVSS 5.5≤ 11.122026-02-07
CVE-2020-37164 [MEDIUM] CWE-120 CVE-2020-37164: AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash
AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.
nvd
CVE-2020-37165P4MEDIUMCVSS 5.5≤ 11.122026-02-07
CVE-2020-37165 [MEDIUM] CWE-120 CVE-2020-37165: AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash
AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash.
nvd