Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)61%—Guildftpd15/10/200816/6/2026
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.
ModificadaAlta (7.5)3.1%—Steve Poulsen Guildftpd3/10/200616/6/2026
Buffer overflow in GuildFTPd 0.999.13 allows remote attackers to have an unknown impact, possibly code execution related to input containing "globbing chars."
ModificadaMedia (5)1.7%—Steve Poulsen Guildftpd31/12/200316/6/2026
GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.
ModificadaAlta (7.5)3.2%—Steve Poulsen Guildftpd18/10/200116/6/2026
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.
ModificadaMedia (4.6)0.33%—Steve Poulsen Guildftpd18/10/200116/6/2026
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
ModificadaMedia (5)1.3%—Steve Poulsen Guildftpd18/10/200116/6/2026
Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character.
ModificadaMedia (5)1.7%—Steve Poulsen Guildftpd18/10/200116/6/2026
Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.
ModificadaAlta (7.5)7.2%—Steve Poulsen Guildftpd8/7/200016/6/2026
Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.