Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | Typsoft FTP Server | 23/11/2004 | 16/6/2026 | TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Crob FTP Server | 23/11/2004 | 16/6/2026 | Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Xlight FTP Server | 23/11/2004 | 16/6/2026 | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Progress WS FTP Server | 29/8/2004 | 16/6/2026 | WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence. | |
| Modificada | Media (5) | 8.2% | 💥 Exploit | South River Technologies Titan FTP Server | 29/8/2004 | 16/6/2026 | Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | South River Technologies Titan FTP Server | 7/7/2004 | 16/6/2026 | Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket. | |
| Modificada | Media (5) | 4.0% | 💥 Exploit | Orenosv Http FTP Server | 26/5/2004 | 16/6/2026 | Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Mollensoft Software Lightweight FTP Server | 24/3/2004 | 16/6/2026 | Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client. | |
| Modificada | Alta (7.5) | 5.8% | — | Ipswitch WS FTP PROIpswitch WS FTP ServerProgress WS FTP Server | 23/3/2004 | 16/6/2026 | Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | HD Soft Windows FTP Server | 17/2/2004 | 16/6/2026 | Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Karjasoft Sami FTP Server | 13/2/2004 | 16/6/2026 | The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters. | |
| Modificada | Media (5) | 1.8% | — | Matrix FTP ServerAI | 6/2/2004 | 16/6/2026 | Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Crob FTP Server | 1/2/2004 | 16/6/2026 | Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string. | |
| Modificada | Baja (2.1) | 0.29% | — | Cerberus FTP Server | 31/12/2003 | 16/6/2026 | Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access. | |
| Modificada | Media (4.3) | 1.2% | — | Bisonftp Server 4 | 31/12/2003 | 16/6/2026 | BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command. | |
| Modificada | Media (5) | 1.7% | — | Pablo Software Solutions Baby FTP Server | 31/12/2003 | 16/6/2026 | Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation. | |
| Modificada | Alta (7.5) | 1.6% | — | Bisonftp Server 4 | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command. | |
| Modificada | Media (4) | 1.4% | — | Pablo Software Solutions Baby FTP Server | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command. | |
| Modificada | Alta (7.5) | 85% | 💥 Exploit | Ipswitch WS FTP ServerProgress WS FTP Server | 22/9/2003 | 16/6/2026 | Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments. | |
| Modificada | Media (5) | 1.6% | — | Crob FTP Server | 6/8/2003 | 16/6/2026 | Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name. | |
| Modificada | Media (5) | 1.7% | — | Crob FTP Server | 3/6/2003 | 16/6/2026 | Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir. | |
| Modificada | Alta (7.5) | 3.9% | — | Cooolsoft Personal FTP Server | 27/5/2003 | 16/6/2026 | Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument. | |
| Modificada | Media (4.6) | 0.48% | — | Selom Ofori Blackmoon FTP Server | 21/5/2003 | 16/6/2026 | BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks. | |
| Modificada | Media (4.6) | 0.31% | — | Selom Ofori Blackmoon FTP Server | 20/5/2003 | 16/6/2026 | BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges. | |
| Modificada | Media (5) | 1.3% | — | Cooolsoft Personal FTP Server | 31/3/2003 | 16/6/2026 | CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. |