Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Steve Poulsen Guildftpd | 31/12/2003 | 16/6/2026 | GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1. | |
| Modificada | Media (5) | 2.3% | — | Thomas Krebs Niteserver Ftpd | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command. | |
| Modificada | Alta (9) | 58% | 💥 Exploit | Proftpd Project Proftpd | 17/11/2003 | 16/6/2026 | ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files. | |
| Modificada | Media (5) | 11% | 💥 Exploit | GNU FileutilsWashington University Wu-ftpd | 17/11/2003 | 16/6/2026 | An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | GNU FileutilsWashington University Wu-ftpd | 17/11/2003 | 16/6/2026 | ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Tellurian Tftpdnt | 20/10/2003 | 16/6/2026 | Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename. | |
| Modificada | Alta (10) | 6.5% | 💥 Exploit | Gtkftpd Gtkftp | 20/10/2003 | 16/6/2026 | Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command. | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Redhat WU FtpdWuftpd Wu-ftpdApple MAC OS XApple MAC OS X Server+4 | 27/8/2003 | 16/6/2026 | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4)… | |
| Modificada | Media (5) | 1.3% | — | Wzdftpd | 7/8/2003 | 16/6/2026 | wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument. | |
| Modificada | Alta (10) | 18% | 💥 Exploit | Proftpd Project Proftpd | 7/8/2003 | 16/6/2026 | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name. | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Atftpd | 2/7/2003 | 16/6/2026 | Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename. | |
| Modificada | Alta (7.5) | 63% | 💥 Exploit | Tftpd32 | 31/12/2002 | 16/6/2026 | Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument. | |
| Modificada | Media (6.4) | 7.0% | 💥 Exploit | Tftpd32 | 31/12/2002 | 16/6/2026 | tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. | |
| Modificada | Media (5) | 0.79% | — | Netbsd Ftpd | 31/12/2002 | 16/6/2026 | ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session. | |
| Modificada | Alta (7.5) | 3.4% | — | Matthew Mondor MmftpdMatthew Mondor Mmmail | 4/10/2002 | 16/6/2026 | Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier. | |
| Modificada | Media (5) | 1.5% | — | Aftpd | 25/3/2002 | 16/6/2026 | AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump. | |
| Modificada | Alta (7.5) | 12% | — | Proftpd Project Proftpd | 31/12/2001 | 16/6/2026 | ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged. | |
| Modificada | Media (5) | 38% | 💥 Exploit | Proftpd Project Proftpd | 31/12/2001 | 16/6/2026 | The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/"… | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | David Madore Ftpd-bsdWashington University Wu-ftpd | 30/11/2001 | 16/6/2026 | wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob). | |
| Modificada | Alta (7.5) | 1.5% | — | Washington University Wu-ftpd | 28/11/2001 | 16/6/2026 | Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550. | |
| Modificada | Media (4.6) | 0.33% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file. | |
| Modificada | Alta (7.5) | 3.2% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command. | |
| Modificada | Media (5) | 1.7% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET. | |
| Modificada | Media (5) | 1.3% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character. | |
| Modificada | Media (5) | 2.0% | — | Charles Clark Meteor Ftpd | 27/9/2001 | 16/6/2026 | Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command. |