Skip to main content

Vendor/product archive

schollz / croc CVEs

Beta · best-effort

6 CVEs tagged to schollz / croc0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-43621

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43620

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43619

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_keys file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43618

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43617

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of comp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43616

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1