glftpd records
7 published records for vendor glftpd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2000-0587No exploit | The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completioglftpd · glftpd | Critical10.0 | — | 4.2% | Jun 26, 2000 |
41Plan | CVE-2000-0040No exploit | glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.glftpd · glftpd | Critical10.0 | — | 1.9% | Dec 23, 1999 |
32Monitor | CVE-2000-0038Proof of concept | glFtpD includes a default glftpd user account with a default password and a UID of 0.glftpd · glftpd | High7.5 | — | 6.6% | Dec 23, 1999 |
31Monitor | CVE-2021-31645No exploit | An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.glftpd · glftpd · CWE-770 | High7.5 | — | 2.0% | Jul 7, 2022 |
30Monitor | CVE-2006-1253No exploit | Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostnglftpd · glftpd | High7.5 | — | 1.5% | Mar 18, 2006 |
22Monitor | CVE-2001-0965Proof of concept | glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a largeglftpd · glftpd | Medium5.0 | — | 7.1% | Aug 31, 2001 |
21Monitor | CVE-2005-0483No exploit | Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticaglftpd · glftpd | Medium5.0 | — | 2.0% | Mar 30, 2005 |
- CVE-2000-058741Plan
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completio
CriticalCVSS 10.0No exploitEPSS 4%glftpd · glftpdJun 26, 2000
- CVE-2000-004041Plan
glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.
CriticalCVSS 10.0No exploitEPSS 2%glftpd · glftpdDec 23, 1999
- CVE-2000-003832Monitor
glFtpD includes a default glftpd user account with a default password and a UID of 0.
HighCVSS 7.5Proof of conceptEPSS 7%glftpd · glftpdDec 23, 1999
- CVE-2021-3164531Monitor
An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.
HighCVSS 7.5No exploitEPSS 2%glftpd · glftpdJul 7, 2022
- CVE-2006-125330Monitor
Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostn
HighCVSS 7.5No exploitEPSS 2%glftpd · glftpdMar 18, 2006
- CVE-2001-096522Monitor
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large
MediumCVSS 5.0Proof of conceptEPSS 7%glftpd · glftpdAug 31, 2001
- CVE-2005-048321Monitor
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authentica
MediumCVSS 5.0No exploitEPSS 2%glftpd · glftpdMar 30, 2005