← Vulnerability feed

Vulnerability record · CVE-2016-2563 · published 7 April 2016

CVE-2016-2563: 9bis kitty memory buffer overflow vulnerability

9bis · Kitty

Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.

9.8 CVSS 3.0 Critical EPSS 34% · top 1.6% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 7.5
34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2563 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-237499bis kitty command injection vulnerabilityKiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and v…EPSS 4.7%7.8CVE-2024-250039bis kitty out-of-bounds write vulnerabilityKiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and i…EPSS 1.8%7.8CVE-2024-250049bis kitty out-of-bounds write vulnerabilityKiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and i…EPSS 1.8%6.8CVE-2013-4852Winscp vulnerabilityInteger overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of ser…EPSS 3.4%6.8CVE-2013-4206Putty memory buffer overflow vulnerabilityHeap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and…EPSS 2.5%5.9CVE-2023-48795SSH Terrapin attack downgrades channel integrity in OpenSSH and many SSH implementationsThe SSH transport protocol with certain OpenSSH extensions mishandles the handshake and sequence numbers, letting a remote attacker omit packets from…EPSS 93%analysed4.3CVE-2015-5309Opensuse leap vulnerabilityInteger overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly e…EPSS 3.5%4.3CVE-2013-4207Putty memory buffer overflow vulnerabilityBuffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is n…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2016-2563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.