Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Yepyep Mtftpd | 2/5/2005 | 16/6/2026 | Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Yepyep Mtftpd | 2/5/2005 | 16/6/2026 | Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command. | |
| Modificada | Alta (7.5) | 11% | — | Gproftpd | 30/3/2005 | 16/6/2026 | Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log. | |
| Modificada | Media (5) | 2.0% | — | Glftpd | 30/3/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot)… | |
| Modificada | Alta (10) | 8.2% | 💥 Exploit | Weonlydo Wodftpdlx Activex Component | 10/1/2005 | 16/6/2026 | Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Media (6.5) | 5.4% | 💥 Exploit | Openftpd FTP Server | 31/12/2004 | 16/6/2026 | Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument. | |
| Modificada | Alta (7.2) | 1.4% | 💥 Exploit | Whitsoft Development Slimftpd | 31/12/2004 | 16/6/2026 | Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT. | |
| Modificada | Media (5) | 2.1% | — | Beasts Vsftpd | 31/12/2004 | 16/6/2026 | vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | WftpdAITexas Imperial Software Wftpd PROAI | 31/12/2004 | 16/6/2026 | The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command. | |
| Modificada | Baja (2.1) | 0.44% | — | Texas Imperial Software Wftpd | 23/11/2004 | 16/6/2026 | WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline. | |
| Modificada | Baja (2.1) | 1.0% | 💥 Exploit | Smallftpd | 23/11/2004 | 16/6/2026 | Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters. | |
| Modificada | Media (5.5) | 0.45% | — | Wftpd PRO Server Project Wftpd PRO Server | 23/11/2004 | 16/6/2026 | WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error. | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Texas Imperial Software Wftpd | 23/11/2004 | 16/6/2026 | Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands. | |
| Modificada | Alta (7.8) | 5.7% | — | Proftpd | 23/11/2004 | 16/6/2026 | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command. | |
| Modificada | Media (5.1) | 2.4% | — | Luke Mewburn LukemftpLuke Mewburn Tnftpd | 20/10/2004 | 16/6/2026 | Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Media (5) | 31% | 💥 Exploit | Proftpd | 15/10/2004 | 16/6/2026 | ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Texas Imperial Software Wftpd | 29/8/2004 | 16/6/2026 | WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands. | |
| Modificada | Alta (7.5) | 9.2% | — | Proftpd Project ProftpdGentoo LinuxTrustix Secure Linux | 18/8/2004 | 16/6/2026 | ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Pureftpd | 6/8/2004 | 16/6/2026 | The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections. | |
| Modificada | Media (5) | 1.8% | — | Oftpd | 4/5/2004 | 16/6/2026 | oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value. | |
| Modificada | Alta (7.2) | 0.44% | — | SGI PropackWashington University Wu-ftpd | 15/4/2004 | 16/6/2026 | wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead. | |
| Modificada | Alta (10) | 7.4% | — | Washington University Wu-ftpd | 15/3/2004 | 16/6/2026 | Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name. | |
| Modificada | Media (5) | 1.2% | — | Beasts Vsftpd | 3/2/2004 | 16/6/2026 | vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames. | |
| Modificada | Alta (9.3) | 3.3% | — | Washington University Wu-ftpd | 31/12/2003 | 16/6/2026 | Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs… | |
| Modificada | Alta (7.8) | 1.3% | — | Washington University Wu-ftpd | 31/12/2003 | 16/6/2026 | ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service. |