Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.8% | — | Oftpd | 4/5/2004 | 16/6/2026 | oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value. | |
| Modificada | Alta (9) | 58% | 💥 Exploit | Proftpd Project Proftpd | 17/11/2003 | 16/6/2026 | ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files. | |
| Modificada | Alta (10) | 18% | 💥 Exploit | Proftpd Project Proftpd | 7/8/2003 | 16/6/2026 | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name. | |
| Modificada | Media (5) | 38% | 💥 Exploit | Proftpd Project Proftpd | 31/12/2001 | 16/6/2026 | The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/"… | |
| Modificada | Alta (7.5) | 12% | — | Proftpd Project Proftpd | 31/12/2001 | 16/6/2026 | ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged. | |
| Modificada | Alta (7.5) | 11% | — | Proftpd Project Proftpd | 2/6/2001 | 16/6/2026 | Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd). | |
| Modificada | Media (5) | 45% | 💥 Exploit | ProftpdConectiva LinuxDebian LinuxMandrakesoft Mandrake Linux | 12/3/2001 | 16/6/2026 | Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed. | |
| Modificada | Alta (7.5) | 6.5% | — | Proftpd Project Proftpd | 12/2/2001 | 16/6/2026 | mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users. | |
| Modificada | Media (4.6) | 4.4% | — | Proftpd Project Proftpd | 19/11/1999 | 16/6/2026 | ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command. | |
| Modificada | Alta (10) | 38% | 💥 Exploit | Proftpd Project Proftpd | 27/8/1999 | 16/6/2026 | Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | |
| Modificada | Alta (10) | 2.2% | — | BeroftpdWashington University Wu-ftpd | 22/8/1999 | 16/6/2026 | Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR. | |
| Modificada | Alta (10) | 40% | 💥 Exploit | Proftpd Project ProftpdWashington University Wu-ftpdCaldera OpenlinuxDebian Linux+4 | 9/2/1999 | 16/6/2026 | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. |