Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1)0.14%—Wolfssl WolftpmAI4/8/202517/6/2026
Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if the default `MAX_RSA_KEY_BITS=2048` is used. If your TPM 2.0 module supports RSA key sizes larger than 2048 bit and your applications supports creating or importing an RSA private or public key larger than 2048 bits and…
ModificadaAlta (7.5)2.0%—Glftpd7/7/202217/6/2026
An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.
ModificadaMedia (6.5)4.8%—Lftp Project LftpCanonical Ubuntu LinuxOpensuse Leap1/8/201817/6/2026
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal…
ModificadaAlta (9.3)2.2%—Estsoft Alftp22/2/201216/6/2026
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
ModificadaAlta (7.5)3.6%—Alexander V. Lukyanov Lftp6/7/201016/6/2026
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly…
ModificadaAlta (9.3)11%—Estsoft Alftp13/6/200816/6/2026
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup…
ModificadaMedia (6.8)3.2%—Alexander V. Lukyanov Lftp27/4/200716/6/2026
mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which…
ModificadaMedia (5)1.3%—Altools Alftp FTP Server17/11/200616/6/2026
Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors related to the REN command, probably due to response messages. NOTE: the provenance of this information is unknown; details are obtained from…
ModificadaMedia (5)1.7%—Altools Alftp FTP Server17/11/200616/6/2026
Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
ModificadaAlta (7.5)1.5%—Glftpd19/3/200616/6/2026
Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.
ModificadaMedia (5)2.0%—Glftpd30/3/200516/6/2026
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot)…
ModificadaBaja (2.1)1.0%—Smallftpd23/11/200416/6/2026
Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.
ModificadaAlta (7.5)14%—Alexander V. Lukyanov Lftp5/1/200416/6/2026
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
ModificadaMedia (5)7.1%—Glftpd31/8/200116/6/2026
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
ModificadaAlta (10)4.3%—Trolltech Trollftpd13/8/200116/6/2026
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.
ModificadaAlta (10)4.2%—Glftpd26/6/200016/6/2026
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.
ModificadaAlta (7.5)6.6%—Glftpd23/12/199916/6/2026
glFtpD includes a default glftpd user account with a default password and a UID of 0.
ModificadaAlta (10)1.9%—Glftpd23/12/199916/6/2026
glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.