Globalscape
Globalscape Cuteftp: vulnerabilities and CVEs
Globalscape Cuteftp has 9 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months1
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25366 | High (8.6) | 0.18% | — | May 25, 2026 | CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520… |
| CVE-2024-1190 | Medium (5.5) | 0.30% | — | Feb 2, 2024 | A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of… |
| CVE-2009-3483 | High (9.3) | 4.7% | — | Sep 30, 2009 | Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a denial of service (memory corruption)… |
| CVE-2008-2779 | High (9.3) | 2.6% | — | Jun 19, 2008 | Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot… |
| CVE-2004-1136 | Medium (5) | 1.1% | — | Jan 10, 2005 | Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands. |
| CVE-2003-1260 | High (7.6) | 8.7% | — | Dec 31, 2003 | Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command. |
| CVE-2003-1261 | Low (2.1) | 0.48% | — | Dec 31, 2003 | Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard. |
| CVE-2003-1259 | High (7.5) | 3.9% | — | Dec 31, 2003 | Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner. |
| CVE-2000-0084 | Medium (5) | 0.88% | — | Jan 6, 2000 | CuteFTP uses weak encryption to store password information in its tree.dat file. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.