Skip to content
Noroxi

proftpd records

34 published records for vendor proftpd.

Researcher profile

Entered KEV
0 · 0%
Weaponized
3 · 8.8%
Pre-auth RCE
5
With a fix record
85.3%
Median publish → KEV
No record has entered KEV

All records

34 records
  • CVE-2015-3306
    69This week

    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

    CriticalCVSS 10.0WeaponizedEPSS 97%

    proftpd · proftpdMay 18, 2015

  • CVE-2010-4221
    67This week

    Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exe

    CriticalCVSS 10.0WeaponizedEPSS 91%

    proftpd · proftpdNov 9, 2010

  • An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without

    CriticalCVSS 9.8Proof of conceptEPSS 58%

    proftpd · proftpdJul 19, 2019

  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 94%

    ssh · sshDec 18, 2023

  • Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via ve

    CriticalCVSS 9.0No exploitEPSS 13%

    proftpd · proftpdDec 6, 2011

  • CVE-2020-9273
    39Monitor

    In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.

    HighCVSS 8.8Proof of conceptEPSS 12%

    proftpd · proftpdFeb 20, 2020

  • ProFTPD 1.3.3c Backdoor Command Execution

    CriticalCVSS 9.3WeaponizedEPSS 5%

    proftpd · proftpdAug 20, 2025

  • ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c

    HighCVSS 7.5Proof of conceptEPSS 20%

    proftpd · proftpdOct 21, 2019

  • mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of US

    HighCVSS 8.1Proof of conceptEPSS 7%

    proftpd · proftpdApr 28, 2026

  • ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly

    HighCVSS 8.7No exploitEPSS 1%

    proftpd · proftpdJul 20, 2026

  • ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR

    HighCVSS 8.6No exploitEPSS 1%

    proftpd · proftpdJun 24, 2026

  • CVE-2001-0136
    33Monitor

    Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman

    MediumCVSS 5.0Proof of conceptEPSS 45%

    proftpd · proftpdMar 12, 2001

  • CVE-2004-0346
    33Monitor

    Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte

    HighCVSS 7.8No exploitEPSS 6%

    proftpd · proftpdNov 23, 2004

  • CVE-2009-0543
    32Monitor

    ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded m

    MediumCVSS 6.8Proof of conceptEPSS 16%

    proftpd · proftpdFeb 12, 2009

  • CVE-2016-3125
    32Monitor

    The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cau

    HighCVSS 7.5No exploitEPSS 7%

    proftpd · proftpdApr 5, 2016

  • make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backsla

    HighCVSS 7.5Proof of conceptEPSS 4%

    proftpd · proftpdDec 21, 2023

  • In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplement

    HighCVSS 7.5Proof of conceptEPSS 2%

    Nov 29, 2024

  • CVE-2020-9272
    31Monitor

    ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.

    HighCVSS 7.5No exploitEPSS 2%

    proftpd · proftpdFeb 20, 2020

  • CVE-2010-4652
    30Monitor

    Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows r

    MediumCVSS 6.8No exploitEPSS 11%

    proftpd · proftpdFeb 1, 2011

  • CVE-2010-3867
    30Monitor

    Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create

    HighCVSS 7.1Proof of conceptEPSS 8%

    proftpd · proftpdNov 9, 2010

  • mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.

    HighCVSS 7.5No exploitEPSS 1%

    proftpd · proftpdNov 23, 2022

  • An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.

    HighCVSS 7.5No exploitEPSS 1%

    proftpd · proftpdNov 26, 2019

  • An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.

    HighCVSS 7.5No exploitEPSS 1%

    proftpd · proftpdNov 26, 2019

  • An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.

    HighCVSS 7.5No exploitEPSS 1%

    proftpd · proftpdNov 26, 2019

  • ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation

    HighCVSS 7.7No exploitEPSS 1%

    proftpd · proftpdJul 18, 2026