Coreftp records
19 published records for vendor coreftp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2018-12113No exploit | Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV coreftp · core ftp · CWE-119 | Critical9.8 | — | 6.9% | Jul 5, 2018 |
39Monitor | CVE-2009-3484Proof of concept | Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname icoreftp · core ftp · CWE-119 | Critical9.3 | — | 5.6% | Sep 30, 2009 |
39Monitor | CVE-2020-19596No exploit | Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.coreftp · core ftp · CWE-120 | Critical9.8 | — | 1.3% | Apr 5, 2021 |
38Monitor | CVE-2013-3930No exploit | Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory nacoreftp · core ftp · CWE-119 | Critical9.3 | — | 3.0% | Apr 4, 2014 |
34Monitor | CVE-2019-25654No exploit | Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflowcoreftp · core ftp · CWE-787 | High8.7 | — | 0.7% | Mar 30, 2026 |
34Monitor | CVE-2019-25686No exploit | Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Servicecoreftp · core ftp · CWE-306 | High8.7 | — | 0.5% | Apr 5, 2026 |
33Monitor | CVE-2018-20658Proof of concept | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted Xcoreftp · core ftp · CWE-20 | High7.5 | — | 8.5% | Jan 2, 2019 |
31Monitor | CVE-2014-1215No exploit | Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data fcoreftp · core ftp · CWE-119 | High7.8 | — | 0.4% | Mar 20, 2018 |
30Monitor | CVE-2020-19595No exploit | Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.coreftp · core ftp · CWE-120 | High7.5 | — | 1.1% | Apr 5, 2021 |
28Monitor | CVE-2022-22836Proof of concept | CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.coreftp · core ftp · CWE-22 | Medium6.5 | — | 5.4% | Jan 10, 2022 |
25Monitor | CVE-2019-9649Proof of concept | An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674.coreftp · core ftp · CWE-22 | Medium5.3 | — | 14.5% | Mar 22, 2019 |
25Monitor | CVE-2019-9648Proof of concept | An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674.coreftp · core ftp · CWE-22 | Medium5.3 | — | 14.3% | Mar 22, 2019 |
23Monitor | CVE-2014-4643Proof of concept | Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (applcoreftp · core ftp · CWE-119 | Medium5.0 | — | 8.8% | Jun 25, 2014 |
22Monitor | CVE-2022-22899No exploit | Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packecoreftp · core ftp · CWE-787 | Medium5.5 | — | 0.9% | Feb 17, 2022 |
22Monitor | CVE-2020-21588No exploit | Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Userncoreftp · core ftp · CWE-120 | Medium5.5 | — | 0.3% | Apr 2, 2021 |
21Monitor | CVE-2013-0130No exploit | Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service coreftp · coreftp · CWE-119 | Medium5.1 | — | 2.3% | Mar 29, 2013 |
18Monitor | CVE-2014-1441No exploit | Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL cocoreftp · core ftp · CWE-362 | Medium4.3 | — | 1.9% | May 1, 2014 |
17Monitor | CVE-2014-1442No exploit | Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arcoreftp · core ftp · CWE-22 | Medium4.0 | — | 2.4% | May 1, 2014 |
17Monitor | CVE-2014-1443No exploit | Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via coreftp · core ftp · CWE-119 | Medium4.0 | — | 1.8% | May 1, 2014 |
- CVE-2018-1211341Plan
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV
CriticalCVSS 9.8No exploitEPSS 7%coreftp · core ftpJul 5, 2018
- CVE-2009-348439Monitor
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname i
CriticalCVSS 9.3Proof of conceptEPSS 6%coreftp · core ftpSep 30, 2009
- CVE-2020-1959639Monitor
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
CriticalCVSS 9.8No exploitEPSS 1%coreftp · core ftpApr 5, 2021
- CVE-2013-393038Monitor
Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory na
CriticalCVSS 9.3No exploitEPSS 3%coreftp · core ftpApr 4, 2014
- CVE-2019-2565434Monitor
Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflow
HighCVSS 8.7No exploitEPSS 1%coreftp · core ftpMar 30, 2026
- CVE-2019-2568634Monitor
Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service
HighCVSS 8.7No exploitEPSS 0%coreftp · core ftpApr 5, 2026
- CVE-2018-2065833Monitor
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted X
HighCVSS 7.5Proof of conceptEPSS 8%coreftp · core ftpJan 2, 2019
- CVE-2014-121531Monitor
Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data f
HighCVSS 7.8No exploitEPSS 0%coreftp · core ftpMar 20, 2018
- CVE-2020-1959530Monitor
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
HighCVSS 7.5No exploitEPSS 1%coreftp · core ftpApr 5, 2021
- CVE-2022-2283628Monitor
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
MediumCVSS 6.5Proof of conceptEPSS 5%coreftp · core ftpJan 10, 2022
- CVE-2019-964925Monitor
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674.
MediumCVSS 5.3Proof of conceptEPSS 15%coreftp · core ftpMar 22, 2019
- CVE-2019-964825Monitor
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674.
MediumCVSS 5.3Proof of conceptEPSS 14%coreftp · core ftpMar 22, 2019
- CVE-2014-464323Monitor
Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (appl
MediumCVSS 5.0Proof of conceptEPSS 9%coreftp · core ftpJun 25, 2014
- CVE-2022-2289922Monitor
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packe
MediumCVSS 5.5No exploitEPSS 1%coreftp · core ftpFeb 17, 2022
- CVE-2020-2158822Monitor
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Usern
MediumCVSS 5.5No exploitEPSS 0%coreftp · core ftpApr 2, 2021
- CVE-2013-013021Monitor
Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service
MediumCVSS 5.1No exploitEPSS 2%coreftp · coreftpMar 29, 2013
- CVE-2014-144118Monitor
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL co
MediumCVSS 4.3No exploitEPSS 2%coreftp · core ftpMay 1, 2014
- CVE-2014-144217Monitor
Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of ar
MediumCVSS 4.0No exploitEPSS 2%coreftp · core ftpMay 1, 2014
- CVE-2014-144317Monitor
Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via
MediumCVSS 4.0No exploitEPSS 2%coreftp · core ftpMay 1, 2014