Записи Filezilla-Project
14 опубликованных записей вендора filezilla-project.
Профиль для исследователя
- Попали в KEV
- 1 · 7,1 %
- С эксплойтом
- 3 · 21,4 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 42,9 %
- Медиана: публикация → KEV
- 2949 дн.
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-125 Out-of-bounds Read1
- CWE-20 Improper Input Validation1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
58В плане | CVE-2014-0224Готовый эксплойт | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Высокая7,4 | — | 95,3 % | 5 июн. 2014 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
37Наблюдать | CVE-2006-6565Готовый эксплойт | FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) Nfilezilla-project · filezilla server · CWE-476 | Средняя4,0 | — | 70,6 % | 15 дек. 2006 г. |
34Наблюдать | CVE-2023-53959Эксплойта нет | FileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dllfilezilla-project · filezilla client · CWE-427 | Высокая8,5 | — | 0,9 % | 19 дек. 2025 г. |
32Наблюдать | CVE-2019-5429Эксплойта нет | Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's homfilezilla-project · filezilla client · CWE-426 | Высокая7,8 | — | 3,0 % | 29 апр. 2019 г. |
31Наблюдать | CVE-2016-15003Эксплойта нет | FileZilla Client Installer uninstall.exe unquoted search pathfilezilla-project · filezilla client · CWE-428 | Высокая7,8 | — | 0,9 % | 18 июл. 2022 г. |
27Наблюдать | CVE-2022-29620Эксплойта нет | FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does nfilezilla-project · filezilla client · CWE-312 | Средняя6,5 | — | 1,9 % | 7 июн. 2022 г. |
27Наблюдать | CVE-2019-25683Эксплойта нет | FileZilla 3.40.0 Denial of Service via Local Searchfilezilla-project · filezilla client · CWE-532 | Средняя6,9 | — | 0,2 % | 5 апр. 2026 г. |
25Наблюдать | CVE-2024-31497Proof of concept | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quiputty · putty · CWE-338 | Средняя5,9 | — | 5,8 % | 15 апр. 2024 г. |
21Наблюдать | CVE-2005-0851Proof of concept | FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loopfilezilla-project · filezilla server · CWE-835 | Средняя5,0 | — | 2,2 % | 2 мая 2005 г. |
21Наблюдать | CVE-2005-0850Proof of concept | FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS devfilezilla-project · filezilla server · CWE-20 | Средняя5,0 | — | 2,2 % | 2 мая 2005 г. |
18Наблюдать | CVE-2009-0884Proof of concept | Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSfilezilla-project · filezilla server · CWE-120 | Средняя4,3 | — | 3,4 % | 12 мар. 2009 г. |
17Наблюдать | CVE-2015-10003Эксплойта нет | FileZilla Server PORT confused deputyfilezilla-project · filezilla server · CWE-441 | Средняя4,3 | — | 0,5 % | 17 июл. 2022 г. |
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2014-022458В плане
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
ВысокаяCVSS 7,4Готовый эксплойтEPSS 95 %openssl · openssl5 июн. 2014 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2006-656537Наблюдать
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) N
СредняяCVSS 4,0Готовый эксплойтEPSS 71 %filezilla-project · filezilla server15 дек. 2006 г.
- CVE-2023-5395934Наблюдать
FileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dll
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %filezilla-project · filezilla client19 дек. 2025 г.
- CVE-2019-542932Наблюдать
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's hom
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %filezilla-project · filezilla client29 апр. 2019 г.
- CVE-2016-1500331Наблюдать
FileZilla Client Installer uninstall.exe unquoted search path
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %filezilla-project · filezilla client18 июл. 2022 г.
- CVE-2022-2962027Наблюдать
FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does n
СредняяCVSS 6,5Эксплойта нетEPSS 2 %filezilla-project · filezilla client7 июн. 2022 г.
- CVE-2019-2568327Наблюдать
FileZilla 3.40.0 Denial of Service via Local Search
СредняяCVSS 6,9Эксплойта нетEPSS 0 %filezilla-project · filezilla client5 апр. 2026 г.
- CVE-2024-3149725Наблюдать
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui
СредняяCVSS 5,9Proof of conceptEPSS 6 %putty · putty15 апр. 2024 г.
- CVE-2005-085121Наблюдать
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop
СредняяCVSS 5,0Proof of conceptEPSS 2 %filezilla-project · filezilla server2 мая 2005 г.
- CVE-2005-085021Наблюдать
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS dev
СредняяCVSS 5,0Proof of conceptEPSS 2 %filezilla-project · filezilla server2 мая 2005 г.
- CVE-2009-088418Наблюдать
Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SS
СредняяCVSS 4,3Proof of conceptEPSS 3 %filezilla-project · filezilla server12 мар. 2009 г.
- CVE-2015-1000317Наблюдать
FileZilla Server PORT confused deputy
СредняяCVSS 4,3Эксплойта нетEPSS 1 %filezilla-project · filezilla server17 июл. 2022 г.