Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.6%💥 ExploitYepyep Mtftpd2/5/200516/6/2026
Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.
ModificadaAlta (7.5)4.4%💥 ExploitYepyep Mtftpd2/5/200516/6/2026
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.
ModificadaAlta (7.5)11%—Gproftpd30/3/200516/6/2026
Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.
ModificadaMedia (5)2.0%—Glftpd30/3/200516/6/2026
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot)…
ModificadaAlta (10)8.2%💥 ExploitWeonlydo Wodftpdlx Activex Component10/1/200516/6/2026
Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.
ModificadaMedia (6.5)5.4%💥 ExploitOpenftpd FTP Server31/12/200416/6/2026
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.
ModificadaAlta (7.2)1.4%💥 ExploitWhitsoft Development Slimftpd31/12/200416/6/2026
Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT.
ModificadaMedia (5)2.1%—Beasts Vsftpd31/12/200416/6/2026
vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant.
ModificadaMedia (5)3.1%💥 ExploitWftpdAITexas Imperial Software Wftpd PROAI31/12/200416/6/2026
The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command.
ModificadaBaja (2.1)0.44%—Texas Imperial Software Wftpd23/11/200416/6/2026
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.
ModificadaBaja (2.1)1.0%💥 ExploitSmallftpd23/11/200416/6/2026
Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.
ModificadaMedia (5.5)0.45%—Wftpd PRO Server Project Wftpd PRO Server23/11/200416/6/2026
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
ModificadaAlta (7.2)1.3%💥 ExploitTexas Imperial Software Wftpd23/11/200416/6/2026
Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.
ModificadaAlta (7.8)5.7%—Proftpd23/11/200416/6/2026
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.
ModificadaMedia (5.1)2.4%—Luke Mewburn LukemftpLuke Mewburn Tnftpd20/10/200416/6/2026
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
ModificadaMedia (5)31%💥 ExploitProftpd15/10/200416/6/2026
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
ModificadaMedia (5)3.1%💥 ExploitTexas Imperial Software Wftpd29/8/200416/6/2026
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.
ModificadaAlta (7.5)9.2%—Proftpd Project ProftpdGentoo LinuxTrustix Secure Linux18/8/200416/6/2026
ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.
ModificadaMedia (5)2.3%💥 ExploitPureftpd6/8/200416/6/2026
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
ModificadaMedia (5)1.8%—Oftpd4/5/200416/6/2026
oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.
ModificadaAlta (7.2)0.44%—SGI PropackWashington University Wu-ftpd15/4/200416/6/2026
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
ModificadaAlta (10)7.4%—Washington University Wu-ftpd15/3/200416/6/2026
Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.
ModificadaMedia (5)1.2%—Beasts Vsftpd3/2/200416/6/2026
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
ModificadaAlta (9.3)3.3%—Washington University Wu-ftpd31/12/200316/6/2026
Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs…
ModificadaAlta (7.8)1.3%—Washington University Wu-ftpd31/12/200316/6/2026
ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.
Orbitaley — Vulnerabilidades