Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 01 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out‑of‑Bounds Handling in TTSSH2 Plugin May Lead to Information Disclosure |
Tue, 28 Jul 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read/Write in TTSSH2 Plugin Causing Information Leakage |
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Teraterm Project
Teraterm Project ttssh2 |
|
| Vendors & Products |
Teraterm Project
Teraterm Project ttssh2 |
Wed, 22 Jul 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read/Write in TTSSH2 Plugin Causing Information Leakage |
Fri, 17 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally. | |
| Weaknesses | CWE-130 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-07-17T13:09:30.703Z
Reserved: 2026-07-10T02:15:09.033Z
Link: CVE-2026-60060
Updated: 2026-07-17T13:09:18.400Z
Status : Deferred
Published: 2026-07-17T05:16:41.360
Modified: 2026-07-17T17:56:08.130
Link: CVE-2026-60060
No data.
OpenCVE Enrichment
Updated: 2026-08-01T08:45:02Z