Smartftp records
7 published records for vendor smartftp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-466 Return of Pointer Value Outside of Expected Range1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2010-4871No exploit | Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.smartftp · smartftp | Critical10.0 | — | 1.5% | Oct 7, 2011 |
37Monitor | CVE-2010-3099No exploit | Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remsmartftp · smartftp · CWE-22 | Critical9.3 | — | 1.4% | Aug 20, 2010 |
32Monitor | CVE-2003-1319No exploit | Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) asmartftp · smartftp | High7.6 | — | 5.0% | Dec 31, 2003 |
31Monitor | CVE-2007-0790Proof of concept | Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.smartftp · smartftp · CWE-119 | High7.5 | — | 4.2% | Feb 6, 2007 |
27Monitor | CVE-2010-5219No exploit | Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the csmartftp · smartftp | Medium6.9 | — | 0.3% | Sep 6, 2012 |
27Monitor | CVE-2018-25234No exploit | SmartFTP Client 9.0.2615.0 Denial of Service via Host Fieldsmartftp · smartftp · CWE-466 | Medium6.9 | — | 0.2% | Mar 30, 2026 |
18Monitor | CVE-2021-47791No exploit | SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Servicesmartftp · smartftp · CWE-770 | Medium4.6 | — | 0.5% | Jan 15, 2026 |
- CVE-2010-487140Plan
Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.
CriticalCVSS 10.0No exploitEPSS 2%smartftp · smartftpOct 7, 2011
- CVE-2010-309937Monitor
Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows rem
CriticalCVSS 9.3No exploitEPSS 1%smartftp · smartftpAug 20, 2010
- CVE-2003-131932Monitor
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a
HighCVSS 7.6No exploitEPSS 5%smartftp · smartftpDec 31, 2003
- CVE-2007-079031Monitor
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
HighCVSS 7.5Proof of conceptEPSS 4%smartftp · smartftpFeb 6, 2007
- CVE-2010-521927Monitor
Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the c
MediumCVSS 6.9No exploitEPSS 0%smartftp · smartftpSep 6, 2012
- CVE-2018-2523427Monitor
SmartFTP Client 9.0.2615.0 Denial of Service via Host Field
MediumCVSS 6.9No exploitEPSS 0%smartftp · smartftpMar 30, 2026
- CVE-2021-4779118Monitor
SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service
MediumCVSS 4.6No exploitEPSS 1%smartftp · smartftpJan 15, 2026