Glftpd
Glftpd: vulnerabilidades y CVE
Glftpd tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-31645 | Alta (7.5) | 2.0% | — | 7 jul 2022 | An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit. |
| CVE-2006-1253 | Alta (7.5) | 1.5% | — | 19 mar 2006 | Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address. |
| CVE-2005-0483 | Media (5) | 2.0% | — | 30 mar 2005 | Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in… |
| CVE-2001-0965 | Media (5) | 7.1% | — | 31 ago 2001 | glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters. |
| CVE-2000-0587 | Alta (10) | 4.2% | — | 26 jun 2000 | The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability. |
| CVE-2000-0038 | Alta (7.5) | 6.6% | — | 23 dic 1999 | glFtpD includes a default glftpd user account with a default password and a UID of 0. |
| CVE-2000-0040 | Alta (10) | 1.9% | — | 23 dic 1999 | glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command. |