Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 74% | 💥 Exploit | Proftpd Project Proftpd | 12/2/2009 | 16/6/2026 | SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql. | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Guildftpd | 15/10/2008 | 16/6/2026 | GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 7.1% | — | Proftpd Project Proftpd | 25/9/2008 | 16/6/2026 | ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser. | |
| Modificada | Alta (7.1) | 3.7% | — | Redhat Vsftpd | 9/7/2008 | 16/6/2026 | Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than… | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Bootmanage AdministratorBootmanage Tftpd | 20/3/2008 | 16/6/2026 | Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename. | |
| Modificada | Media (5.8) | 3.1% | 💥 Exploit | Texas Imperial Software Wftpd PRO Explorer | 20/12/2007 | 16/6/2026 | Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command. | |
| Modificada | Media (5) | 4.9% | 💥 Exploit | Wzdftpd | 9/10/2007 | 16/6/2026 | Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Smbftpd | 3/10/2007 | 16/6/2026 | Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name. | |
| Modificada | Alta (10) | 3.6% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 13/5/2007 | 16/6/2026 | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.5% | — | Raiden Professional Servers Raidenftpd | 24/4/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving the (1) CalculateCrc, (2) Compress, and (3) Uncompress functions, which result in a NULL pointer dereference. | |
| Modificada | Media (5.1) | 12% | — | Proftpd Project Proftpd | 22/4/2007 | 16/6/2026 | The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of… | |
| Modificada | Media (5) | 1.3% | — | Bftpd | 16/4/2007 | 16/6/2026 | Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable. | |
| Modificada | Media (6.8) | 1.6% | — | Bftpd | 12/4/2007 | 16/6/2026 | Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command. | |
| Modificada | Alta (10) | 4.8% | — | Hpaftpd | 28/3/2007 | 16/6/2026 | Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command. | |
| Modificada | Media (6.3) | 2.4% | 💥 Exploit | Ftpdmin | 21/3/2007 | 16/6/2026 | FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using "//A:". NOTE: this has been reported as a buffer overflow by some sources, but there is not a long argument. | |
| Modificada | Alta (7.3) | 68% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 10/3/2007 | 16/6/2026 | tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948. | |
| Modificada | Alta (8.5) | 2.6% | — | Ftpd | 2/3/2007 | 16/6/2026 | ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors. | |
| Modificada | Alta (7.8) | 3.8% | 💥 Exploit | H. Nomura Tiny Ftpd | 12/2/2007 | 16/6/2026 | Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long USER command, a different vector than CVE-2000-0133. | |
| Modificada | Media (5) | 3.1% | — | Wzdftpd | 23/1/2007 | 16/6/2026 | Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Texas Imperial Software WftpdTexas Imperial Software Wftpd PRO Server | 18/1/2007 | 16/6/2026 | Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Time-travellers Oftpd | 16/1/2007 | 16/6/2026 | oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure. | |
| Modificada | Media (6.6) | 2.3% | 💥 Exploit | Proftpd Project Proftpd | 15/12/2006 | 16/6/2026 | Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value. | |
| Modificada | Alta (7.5) | 9.7% | — | Proftpd Project Proftpd | 30/11/2006 | 16/6/2026 | ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a… | |
| Modificada | Alta (7.5) | 17% | — | Proftpd Project Proftpd | 30/11/2006 | 16/6/2026 | Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different vulnerability than CVE-2006-5815. | |
| Modificada | Media (5) | 3.8% | — | Philippe Jounin Tftpd32 | 28/11/2006 | 16/6/2026 | Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window. |