Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.7%—Steve Poulsen Guildftpd31/12/200316/6/2026
GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.
ModificadaMedia (5)2.3%—Thomas Krebs Niteserver Ftpd31/12/200316/6/2026
Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.
ModificadaAlta (9)58%💥 ExploitProftpd Project Proftpd17/11/200316/6/2026
ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.
ModificadaMedia (5)11%💥 ExploitGNU FileutilsWashington University Wu-ftpd17/11/200316/6/2026
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.
ModificadaBaja (2.1)1.1%💥 ExploitGNU FileutilsWashington University Wu-ftpd17/11/200316/6/2026
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.
ModificadaAlta (7.5)10%💥 ExploitTellurian Tftpdnt20/10/200316/6/2026
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
ModificadaAlta (10)6.5%💥 ExploitGtkftpd Gtkftp20/10/200316/6/2026
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.
ModificadaCrítica (9.8)78%💥 ExploitRedhat WU FtpdWuftpd Wu-ftpdApple MAC OS XApple MAC OS X Server+427/8/200316/6/2026
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4)…
ModificadaMedia (5)1.3%—Wzdftpd7/8/200316/6/2026
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.
ModificadaAlta (10)18%💥 ExploitProftpd Project Proftpd7/8/200316/6/2026
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
ModificadaAlta (7.5)5.8%💥 ExploitAtftpd2/7/200316/6/2026
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.
ModificadaAlta (7.5)63%💥 ExploitTftpd3231/12/200216/6/2026
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.
ModificadaMedia (6.4)7.0%💥 ExploitTftpd3231/12/200216/6/2026
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
ModificadaMedia (5)0.79%—Netbsd Ftpd31/12/200216/6/2026
ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.
ModificadaAlta (7.5)3.4%—Matthew Mondor MmftpdMatthew Mondor Mmmail4/10/200216/6/2026
Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
ModificadaMedia (5)1.5%—Aftpd25/3/200216/6/2026
AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump.
ModificadaAlta (7.5)12%—Proftpd Project Proftpd31/12/200116/6/2026
ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.
ModificadaMedia (5)38%💥 ExploitProftpd Project Proftpd31/12/200116/6/2026
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/"…
ModificadaAlta (7.5)75%💥 ExploitDavid Madore Ftpd-bsdWashington University Wu-ftpd30/11/200116/6/2026
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
ModificadaAlta (7.5)1.5%—Washington University Wu-ftpd28/11/200116/6/2026
Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.
ModificadaMedia (4.6)0.33%—Steve Poulsen Guildftpd18/10/200116/6/2026
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
ModificadaAlta (7.5)3.2%—Steve Poulsen Guildftpd18/10/200116/6/2026
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.
ModificadaMedia (5)1.7%—Steve Poulsen Guildftpd18/10/200116/6/2026
Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.
ModificadaMedia (5)1.3%—Steve Poulsen Guildftpd18/10/200116/6/2026
Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character.
ModificadaMedia (5)2.0%—Charles Clark Meteor Ftpd27/9/200116/6/2026
Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command.
Orbitaley — Vulnerabilidades