Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 7.6% | 💥 Exploit | Philippe Jounin Tftpd32 | 21/1/2006 | 16/6/2026 | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request. | |
| Modificada | Alta (7.5) | 3.8% | — | Cambridge Computer Corporation Vxtftpsrv | 22/9/2005 | 16/6/2026 | Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument. | |
| Modificada | Alta (7.8) | 3.3% | — | Futuresoft Tftp Server 2000 | 1/6/2005 | 16/6/2026 | Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences. | |
| Modificada | Alta (10) | 63% | 💥 Exploit | Futuresoft Tftp Server 2000 | 1/6/2005 | 16/6/2026 | Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Yepyep Mtftpd | 2/5/2005 | 16/6/2026 | Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Yepyep Mtftpd | 2/5/2005 | 16/6/2026 | Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command. | |
| Modificada | Media (5) | 2.5% | — | Winagents Tftp ServerAI | 31/12/2004 | 16/6/2026 | WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow. | |
| Modificada | Alta (10) | 8.1% | 💥 Exploit | Robotftp Server | 23/11/2004 | 16/6/2026 | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username. | |
| Modificada | Alta (10) | 8.3% | 💥 Exploit | NET Integration Technologies Inc. Wvtftp | 26/10/2004 | 16/6/2026 | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet. | |
| Modificada | Alta (7.6) | 5.0% | — | Smartftp | 31/12/2003 | 16/6/2026 | Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Tellurian Tftpdnt | 20/10/2003 | 16/6/2026 | Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename. | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Atftpd | 2/7/2003 | 16/6/2026 | Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Solarwinds Tftp Server | 31/3/2003 | 16/6/2026 | SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 1.8% | — | Tftp Server | 31/12/2002 | 16/6/2026 | tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux. | |
| Modificada | Media (6.4) | 7.0% | 💥 Exploit | Tftpd32 | 31/12/2002 | 16/6/2026 | tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. | |
| Modificada | Alta (7.5) | 63% | 💥 Exploit | Tftpd32 | 31/12/2002 | 16/6/2026 | Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument. | |
| Modificada | Alta (7.2) | 0.42% | — | Remi Lefebvre Advanced Tftp | 31/12/2002 | 16/6/2026 | Buffer overflow in Advanced TFTP (atftp) 0.5 and 0.6, if installed setuid or setgid, may allow local users to execute arbitrary code via a long argument to the -g option. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Solarwinds Tftp Server | 4/11/2002 | 16/6/2026 | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request. | |
| Modificada | Media (5) | 1.7% | — | Cisco Tftp Server | 18/10/2001 | 16/6/2026 | Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command. | |
| Modificada | Alta (7.5) | 4.2% | — | IBM Alphaworks Tftp Server | 20/7/2001 | 16/6/2026 | Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack. | |
| Modificada | Baja (2.1) | 0.48% | — | Mindstorm Smartftp Daemon | 13/6/2000 | 16/6/2026 | SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack. | |
| Modificada | Media (5.1) | 1.7% | 💥 Exploit | Toxsoft Nextftp | 3/8/1999 | 16/6/2026 | Buffer overflow in ToxSoft NextFTP client through CWD command. | |
| Modificada | Media (6.4) | 1.6% | — | TftpLinux Kernel | 1/9/1997 | 16/6/2026 | Linux implementations of TFTP would allow access to files outside the restricted directory. |