Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.44% | — | Proftpd | 4/4/2017 | 17/6/2026 | ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks… | |
| Modificada | Alta (7.5) | 7.0% | — | ProftpdOpensuseFedoraproject Fedora | 5/4/2016 | 17/6/2026 | The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (5) | 2.7% | — | Netbsd Tnftpd | 9/10/2015 | 17/6/2026 | The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring. | |
| Modificada | Alta (10) | 97% | 💥 Exploit | Proftpd | 18/5/2015 | 17/6/2026 | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | |
| Modificada | Media (5) | 6.8% | 💥 Exploit | OpensuseVsftpd Project Vsftpd | 28/1/2015 | 17/6/2026 | Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing. | |
| Modificada | Alta (10) | 3.5% | — | Jgaa Warftpd | 1/4/2014 | 16/6/2026 | Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to log messages and the "internal log handler to the Windows Event log." | |
| Modificada | Media (4) | 2.7% | 💥 Exploit | Jgaa Warftpd | 1/4/2014 | 16/6/2026 | Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST command. | |
| Modificada | Media (5) | 2.9% | — | Philippe Jounin Tftpd32 | 13/12/2013 | 17/6/2026 | Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field. | |
| Modificada | Media (5) | 3.0% | — | Proftpd | 30/9/2013 | 16/6/2026 | Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation. | |
| Modificada | Baja (1.2) | 0.69% | — | Proftpd | 24/1/2013 | 16/6/2026 | ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands. | |
| Modificada | Alta (10) | 3.1% | — | Freeftpd | 4/12/2012 | 16/6/2026 | freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c. | |
| Modificada | Media (4) | 2.9% | 💥 Exploit | Elif Keir Knftpd | 17/11/2012 | 16/6/2026 | Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command. | |
| Modificada | Alta (9) | 13% | — | Proftpd | 6/12/2011 | 16/6/2026 | Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer. | |
| Modificada | Baja (3.6) | 0.58% | 💥 Exploit | Pureftpd Pure-ftpd | 4/11/2011 | 16/6/2026 | Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors. | |
| Modificada | Media (4) | 7.3% | 💥 Exploit | Pureftpd Pure-ftpdNetbsd | 24/5/2011 | 16/6/2026 | The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command. | |
| Modificada | Media (5.8) | 33% | 💥 PoC | Pureftpd Pure-ftpd | 23/5/2011 | 16/6/2026 | The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection"… | |
| Modificada | Media (4.4) | 0.34% | — | Pureftpd Pure-ftpdNovell Suse Linux | 18/4/2011 | 16/6/2026 | pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors. | |
| Modificada | Media (5) | 28% | 💥 Exploit | Proftpd | 11/3/2011 | 16/6/2026 | Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message. | |
| Modificada | Media (4) | 74% | 💥 Exploit | Vsftpd Project VsftpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+2 | 2/3/2011 | 16/6/2026 | The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632. | |
| Modificada | Media (6.8) | 11% | — | Proftpd | 2/2/2011 | 16/6/2026 | Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during… | |
| Modificada | Alta (10) | 91% | 💥 Exploit | Proftpd | 9/11/2010 | 16/6/2026 | Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server. | |
| Modificada | Alta (7.1) | 7.6% | 💥 Exploit | Proftpd | 9/11/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modify file timestamps via directory traversal sequences in a (1) SITE MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE… | |
| Modificada | Media (4) | 3.2% | — | Proftpd | 9/11/2010 | 16/6/2026 | The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer. | |
| Modificada | Media (4.3) | 2.3% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected value of None for the address, or an ECONNABORTED,… | |
| Modificada | Media (4) | 1.7% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Memory leak in the on_dtp_close function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to cause a denial of service (memory consumption) by sending a QUIT command during a data transfer. |