proftpd records
34 published records for vendor proftpd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 8.8%
- Pre-auth RCE
- 5
- With a fix record
- 85.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-295 Improper Certificate Validation2
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-189 Numeric Errors2
- CWE-125 Out-of-bounds Read2
- CWE-399 Resource Management Errors2
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
69This week | CVE-2015-3306Weaponized | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.proftpd · proftpd · CWE-284 | Critical10.0 | — | 96.8% | May 18, 2015 |
67This week | CVE-2010-4221Weaponized | Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exeproftpd · proftpd · CWE-119 | Critical10.0 | — | 91.3% | Nov 9, 2010 |
56Plan | CVE-2019-12815Proof of concept | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure withoutproftpd · proftpd · CWE-755 | Critical9.8 | — | 57.6% | Jul 19, 2019 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
40Plan | CVE-2011-4130No exploit | Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via veproftpd · proftpd · CWE-399 | Critical9.0 | — | 12.6% | Dec 6, 2011 |
39Monitor | CVE-2020-9273Proof of concept | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.proftpd · proftpd · CWE-416 | High8.8 | — | 12.0% | Feb 20, 2020 |
39Monitor | CVE-2010-20103Weaponized | ProFTPD 1.3.3c Backdoor Command Executionproftpd · proftpd · CWE-912 | Critical9.3 | — | 5.1% | Aug 20, 2025 |
36Monitor | CVE-2019-18217Proof of concept | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long cproftpd · proftpd · CWE-835 | High7.5 | — | 20.3% | Oct 21, 2019 |
34Monitor | CVE-2026-42167Proof of concept | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USproftpd · proftpd · CWE-89 | High8.1 | — | 7.3% | Apr 28, 2026 |
34Monitor | CVE-2026-63090No exploit | ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassemblyproftpd · proftpd · CWE-122 | High8.7 | — | 0.9% | Jul 20, 2026 |
34Monitor | CVE-2026-35025No exploit | ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFRproftpd · proftpd · CWE-59 | High8.6 | — | 0.5% | Jun 24, 2026 |
33Monitor | CVE-2001-0136Proof of concept | Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commanproftpd · proftpd · CWE-401 | Medium5.0 | — | 44.9% | Mar 12, 2001 |
33Monitor | CVE-2004-0346No exploit | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte proftpd · proftpd · CWE-193 | High7.8 | — | 5.7% | Nov 23, 2004 |
32Monitor | CVE-2009-0543Proof of concept | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded mproftpd · proftpd · CWE-89 | Medium6.8 | — | 15.8% | Feb 12, 2009 |
32Monitor | CVE-2016-3125No exploit | The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cauproftpd · proftpd · CWE-254 | High7.5 | — | 7.0% | Apr 5, 2016 |
31Monitor | CVE-2023-51713Proof of concept | make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslaproftpd · proftpd · CWE-125 | High7.5 | — | 4.2% | Dec 21, 2023 |
31Monitor | CVE-2024-48651Proof of concept | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplementCWE-863 | High7.5 | — | 2.2% | Nov 29, 2024 |
31Monitor | CVE-2020-9272No exploit | ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.proftpd · proftpd · CWE-125 | High7.5 | — | 2.1% | Feb 20, 2020 |
30Monitor | CVE-2010-4652No exploit | Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows rproftpd · proftpd · CWE-119 | Medium6.8 | — | 11.2% | Feb 1, 2011 |
30Monitor | CVE-2010-3867Proof of concept | Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to createproftpd · proftpd · CWE-22 | High7.1 | — | 7.6% | Nov 9, 2010 |
30Monitor | CVE-2021-46854No exploit | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.proftpd · proftpd · CWE-401 | High7.5 | — | 1.2% | Nov 23, 2022 |
30Monitor | CVE-2019-19271No exploit | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.proftpd · proftpd · CWE-295 | High7.5 | — | 1.1% | Nov 26, 2019 |
30Monitor | CVE-2019-19270No exploit | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.proftpd · proftpd · CWE-295 | High7.5 | — | 1.0% | Nov 26, 2019 |
30Monitor | CVE-2019-19272No exploit | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.proftpd · proftpd · CWE-476 | High7.5 | — | 0.9% | Nov 26, 2019 |
30Monitor | CVE-2026-53994No exploit | ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncationproftpd · proftpd · CWE-122 | High7.7 | — | 0.7% | Jul 18, 2026 |
- CVE-2015-330669This week
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CriticalCVSS 10.0WeaponizedEPSS 97%proftpd · proftpdMay 18, 2015
- CVE-2010-422167This week
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exe
CriticalCVSS 10.0WeaponizedEPSS 91%proftpd · proftpdNov 9, 2010
- CVE-2019-1281556Plan
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without
CriticalCVSS 9.8Proof of conceptEPSS 58%proftpd · proftpdJul 19, 2019
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2011-413040Plan
Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via ve
CriticalCVSS 9.0No exploitEPSS 13%proftpd · proftpdDec 6, 2011
- CVE-2020-927339Monitor
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.
HighCVSS 8.8Proof of conceptEPSS 12%proftpd · proftpdFeb 20, 2020
- CVE-2010-2010339Monitor
ProFTPD 1.3.3c Backdoor Command Execution
CriticalCVSS 9.3WeaponizedEPSS 5%proftpd · proftpdAug 20, 2025
- CVE-2019-1821736Monitor
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c
HighCVSS 7.5Proof of conceptEPSS 20%proftpd · proftpdOct 21, 2019
- CVE-2026-4216734Monitor
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of US
HighCVSS 8.1Proof of conceptEPSS 7%proftpd · proftpdApr 28, 2026
- CVE-2026-6309034Monitor
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
HighCVSS 8.7No exploitEPSS 1%proftpd · proftpdJul 20, 2026
- CVE-2026-3502534Monitor
ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
HighCVSS 8.6No exploitEPSS 1%proftpd · proftpdJun 24, 2026
- CVE-2001-013633Monitor
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman
MediumCVSS 5.0Proof of conceptEPSS 45%proftpd · proftpdMar 12, 2001
- CVE-2004-034633Monitor
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte
HighCVSS 7.8No exploitEPSS 6%proftpd · proftpdNov 23, 2004
- CVE-2009-054332Monitor
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded m
MediumCVSS 6.8Proof of conceptEPSS 16%proftpd · proftpdFeb 12, 2009
- CVE-2016-312532Monitor
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cau
HighCVSS 7.5No exploitEPSS 7%proftpd · proftpdApr 5, 2016
- CVE-2023-5171331Monitor
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backsla
HighCVSS 7.5Proof of conceptEPSS 4%proftpd · proftpdDec 21, 2023
- CVE-2024-4865131Monitor
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplement
HighCVSS 7.5Proof of conceptEPSS 2%Nov 29, 2024
- CVE-2020-927231Monitor
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
HighCVSS 7.5No exploitEPSS 2%proftpd · proftpdFeb 20, 2020
- CVE-2010-465230Monitor
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows r
MediumCVSS 6.8No exploitEPSS 11%proftpd · proftpdFeb 1, 2011
- CVE-2010-386730Monitor
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create
HighCVSS 7.1Proof of conceptEPSS 8%proftpd · proftpdNov 9, 2010
- CVE-2021-4685430Monitor
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
HighCVSS 7.5No exploitEPSS 1%proftpd · proftpdNov 23, 2022
- CVE-2019-1927130Monitor
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
HighCVSS 7.5No exploitEPSS 1%proftpd · proftpdNov 26, 2019
- CVE-2019-1927030Monitor
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.
HighCVSS 7.5No exploitEPSS 1%proftpd · proftpdNov 26, 2019
- CVE-2019-1927230Monitor
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
HighCVSS 7.5No exploitEPSS 1%proftpd · proftpdNov 26, 2019
- CVE-2026-5399430Monitor
ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation
HighCVSS 7.7No exploitEPSS 1%proftpd · proftpdJul 18, 2026