Open Tftp Server Project
Open Tftp Server Project Open Tftp Server: vulnerabilidades y CVE
Open Tftp Server Project Open Tftp Server tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-26130 | Alta (7.8) | 0.44% | — | 28 oct 2020 | Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by… |
| CVE-2019-12568 | Crítica (9.8) | 2.3% | — | 23 dic 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a… |
| CVE-2019-12567 | Crítica (9.8) | 2.3% | — | 23 dic 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a… |
| CVE-2018-10389 | Crítica (9.8) | 2.3% | — | 23 dic 2019 | Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. |
| CVE-2018-10388 | Crítica (9.8) | 4.4% | — | 23 dic 2019 | Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. |
| CVE-2018-10387 | Crítica (9.8) | 2.9% | — | 23 dic 2019 | Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than… |