Pureftpd
Pureftpd Pure-ftpd: vulnerabilidades y CVE
Pureftpd Pure-ftpd tiene 12 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-58383 | Alta (8.4) | 0.10% | — | 14 sept 2026 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL… |
| CVE-2024-48208 | Alta (8.6) | 1.6% | — | 24 oct 2024 | pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file. |
| CVE-2021-40524 | Alta (7.5) | 4.3% | — | 5 sept 2021 | In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain… |
| CVE-2020-35359 | Alta (7.5) | 4.5% | — | 26 dic 2020 | Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit. |
| CVE-2020-9274 | Alta (7.5) | 6.0% | — | 26 feb 2020 | An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called,… |
| CVE-2020-9365 | Alta (7.5) | 7.1% | — | 24 feb 2020 | An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c. |
| CVE-2019-20176 | Alta (7.5) | 4.4% | — | 31 dic 2019 | In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. |
| CVE-2017-12170 | Crítica (9.8) | 1.5% | — | 21 sept 2017 | Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration.… |
| CVE-2011-3171 | Baja (3.6) | 0.58% | — | 4 nov 2011 | Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is… |
| CVE-2011-0418 | Media (4) | 7.3% | — | 24 may 2011 | The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory… |
| CVE-2011-1575 | Media (5.8) | 33% | — | 23 may 2011 | The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a… |
| CVE-2011-0988 | Media (4.4) | 0.34% | — | 18 abr 2011 | pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.