Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.1)0.18%—BftpdAI19/10/202517/6/2026
A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack on the local host. Attacks of this nature are highly complex.…
ModificadaCrítica (9.8)2.0%—Bftpd Project Bftpd10/1/202017/6/2026
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
ModificadaCrítica (9.1)1.7%—Bftpd Project Bftpd10/1/202017/6/2026
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.
ModificadaAlta (7.5)1.2%—Bftpd Project Bftpd19/11/201717/6/2026
In Bftpd before 4.7, there is a memory leak in the file rename function.
ModificadaMedia (5)1.4%—Jesse Smith Bftpd7/1/201016/6/2026
The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third…
ModificadaAlta (7.5)12%—Smbftpd3/10/200716/6/2026
Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.
ModificadaMedia (5)1.3%—Bftpd16/4/200716/6/2026
Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable.
ModificadaMedia (6.8)1.6%—Bftpd12/4/200716/6/2026
Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.
ModificadaAlta (10)4.8%—Max-wilhelm Bruker Bftpd12/2/200116/6/2026
Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.
ModificadaAlta (7.5)3.8%—Max-wilhelm Bruker Bftpd19/12/200023/9/2026
Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.