Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.1) | 0.18% | — | BftpdAI | 19/10/2025 | 17/6/2026 | A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack on the local host. Attacks of this nature are highly complex.… | |
| Modificada | Crítica (9.8) | 2.0% | — | Bftpd Project Bftpd | 10/1/2020 | 17/6/2026 | An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking. | |
| Modificada | Crítica (9.1) | 1.7% | — | Bftpd Project Bftpd | 10/1/2020 | 17/6/2026 | An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c. | |
| Modificada | Alta (7.5) | 1.2% | — | Bftpd Project Bftpd | 19/11/2017 | 17/6/2026 | In Bftpd before 4.7, there is a memory leak in the file rename function. | |
| Modificada | Media (5) | 1.4% | — | Jesse Smith Bftpd | 7/1/2010 | 16/6/2026 | The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 12% | — | Smbftpd | 3/10/2007 | 16/6/2026 | Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name. | |
| Modificada | Media (5) | 1.3% | — | Bftpd | 16/4/2007 | 16/6/2026 | Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable. | |
| Modificada | Media (6.8) | 1.6% | — | Bftpd | 12/4/2007 | 16/6/2026 | Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command. | |
| Modificada | Alta (10) | 4.8% | — | Max-wilhelm Bruker Bftpd | 12/2/2001 | 16/6/2026 | Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command. | |
| Modificada | Alta (7.5) | 3.8% | — | Max-wilhelm Bruker Bftpd | 19/12/2000 | 23/9/2026 | Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command. |