KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.
Conclusion & alert: CVE-2024-25004 is rated High Exploit Risk (70.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.61%). Core evidence: 4 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 51891 | exploit_db | edb | 2024-03-14 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-27 | 0.45% | 0.61% | +0.16% |
| 2 | 2025-11-21 | 0.36% | 0.45% | +0.09% |
| 3 | 2025-11-18 | — | 0.36% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-25004: 1 source package rows (kitty); 41 state rows across 5 repos (3.19-community, 3.20-community, 3.22-community, 3.23-community, edge-community); fixed 0, open 41. | https://security.alpinelinux.org/vuln/CVE-2024-25004 |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/177031/KiTTY-0.76.1.13-Command-Injection.html | |
| http://packetstormsecurity.com/files/177032/KiTTY-0.76.1.13-Buffer-Overflows.html | Third Party Advisory VDB Entry |
| http://seclists.org/fulldisclosure/2024/Feb/13 | Exploit Mailing List |
| http://seclists.org/fulldisclosure/2024/Feb/14 | Exploit Mailing List |
| https://blog.defcesco.io/CVE-2024-25003-CVE-2024-25004 | Exploit Third Party Advisory |