Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 11% | 💥 Exploit | Texas Imperial Software Wftpd | 10/11/2006 | 16/6/2026 | Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters. | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Proftpd Project Proftpd | 8/11/2006 | 16/6/2026 | Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit." | |
| Modificada | Media (4) | 2.9% | 💥 Exploit | Jgaa Warftpd | 7/11/2006 | 16/6/2026 | War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands. NOTE: it is possible that vector 1 is an off-by-one variant or incomplete fix of… | |
| Modificada | Media (4.6) | 0.37% | — | Linux-ftpd-ssl | 7/11/2006 | 16/6/2026 | ftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory. | |
| Modificada | Alta (7.5) | 3.1% | — | Steve Poulsen Guildftpd | 3/10/2006 | 16/6/2026 | Buffer overflow in GuildFTPd 0.999.13 allows remote attackers to have an unknown impact, possibly code execution related to input containing "globbing chars." | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 23/9/2006 | 16/6/2026 | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (6.5) | 62% | 💥 Exploit | Texas Imperial Software Wftpd | 24/8/2006 | 16/6/2026 | Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands. | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | FreeftpdFreesshdWeonlydo Wodsshserver | 16/5/2006 | 16/6/2026 | Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string. | |
| Modificada | Media (6.4) | 4.6% | — | Jgaa Warftpd | 4/5/2006 | 16/6/2026 | Buffer overflow in WDM.exe in WarFTPD allows remote attackers to execute arbitrary code via unspecified arguments, as demonstrated by the Infigo FTPStress Fuzzer. | |
| Modificada | Alta (7.5) | 1.5% | — | Glftpd | 19/3/2006 | 16/6/2026 | Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Philippe Jounin Tftpd32 | 21/1/2006 | 16/6/2026 | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request. | |
| Modificada | Media (5) | 1.4% | — | Inicom Networks Ioftpd | 31/12/2005 | 16/6/2026 | ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Alta (7.5) | 13% | — | Proftpd Project Proftpd | 31/12/2005 | 16/6/2026 | Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Freeftpd | 26/11/2005 | 16/6/2026 | freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Freeftpd | 19/11/2005 | 16/6/2026 | Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Freeftpd | 19/11/2005 | 16/6/2026 | Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command. | |
| Modificada | Alta (10) | 21% | 💥 Exploit | Linux-ftpd-ssl | 7/11/2005 | 16/6/2026 | Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command. | |
| Modificada | Media (4.6) | 77% | 💥 Exploit | Wzdftpd | 27/9/2005 | 16/6/2026 | wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Whitsoft Development Slimftpd | 8/9/2005 | 16/6/2026 | SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error. | |
| Modificada | Media (6.4) | 9.2% | — | Proftpd Project Proftpd | 27/7/2005 | 16/6/2026 | Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive. | |
| Modificada | Alta (7.2) | 46% | 💥 Exploit | Whitsoft Development Slimftpd | 26/7/2005 | 16/6/2026 | Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands. | |
| Modificada | Alta (7.5) | 1.9% | — | Phpsftpd | 19/7/2005 | 16/6/2026 | inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Oftpd | 12/7/2005 | 16/6/2026 | oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Raiden Professional Servers Raidenftpd | 11/5/2005 | 16/6/2026 | Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in the urlget site command. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Washington University Wu-ftpd | 2/5/2005 | 16/6/2026 | The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command. |