Записи proftpd
34 опубликованных записей вендора proftpd.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 8,8 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 85,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-295 Improper Certificate Validation2
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-189 Numeric Errors2
- CWE-125 Out-of-bounds Read2
- CWE-399 Resource Management Errors2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
69На этой неделе | CVE-2015-3306Готовый эксплойт | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.proftpd · proftpd · CWE-284 | Критическая10,0 | — | 96,8 % | 18 мая 2015 г. |
67На этой неделе | CVE-2010-4221Готовый эксплойт | Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exeproftpd · proftpd · CWE-119 | Критическая10,0 | — | 91,3 % | 9 нояб. 2010 г. |
56В плане | CVE-2019-12815Proof of concept | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure withoutproftpd · proftpd · CWE-755 | Критическая9,8 | — | 57,6 % | 19 июл. 2019 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
40В плане | CVE-2011-4130Эксплойта нет | Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via veproftpd · proftpd · CWE-399 | Критическая9,0 | — | 12,6 % | 6 дек. 2011 г. |
39Наблюдать | CVE-2020-9273Proof of concept | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.proftpd · proftpd · CWE-416 | Высокая8,8 | — | 12,0 % | 20 февр. 2020 г. |
39Наблюдать | CVE-2010-20103Готовый эксплойт | ProFTPD 1.3.3c Backdoor Command Executionproftpd · proftpd · CWE-912 | Критическая9,3 | — | 5,1 % | 20 авг. 2025 г. |
36Наблюдать | CVE-2019-18217Proof of concept | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long cproftpd · proftpd · CWE-835 | Высокая7,5 | — | 20,3 % | 21 окт. 2019 г. |
34Наблюдать | CVE-2026-42167Proof of concept | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USproftpd · proftpd · CWE-89 | Высокая8,1 | — | 7,3 % | 28 апр. 2026 г. |
34Наблюдать | CVE-2026-63090Эксплойта нет | ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassemblyproftpd · proftpd · CWE-122 | Высокая8,7 | — | 0,9 % | 20 июл. 2026 г. |
34Наблюдать | CVE-2026-35025Эксплойта нет | ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFRproftpd · proftpd · CWE-59 | Высокая8,6 | — | 0,5 % | 24 июн. 2026 г. |
33Наблюдать | CVE-2001-0136Proof of concept | Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commanproftpd · proftpd · CWE-401 | Средняя5,0 | — | 44,9 % | 12 мар. 2001 г. |
33Наблюдать | CVE-2004-0346Эксплойта нет | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte proftpd · proftpd · CWE-193 | Высокая7,8 | — | 5,7 % | 23 нояб. 2004 г. |
32Наблюдать | CVE-2009-0543Proof of concept | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded mproftpd · proftpd · CWE-89 | Средняя6,8 | — | 15,8 % | 12 февр. 2009 г. |
32Наблюдать | CVE-2016-3125Эксплойта нет | The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cauproftpd · proftpd · CWE-254 | Высокая7,5 | — | 7,0 % | 5 апр. 2016 г. |
31Наблюдать | CVE-2023-51713Proof of concept | make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslaproftpd · proftpd · CWE-125 | Высокая7,5 | — | 4,2 % | 21 дек. 2023 г. |
31Наблюдать | CVE-2024-48651Proof of concept | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplementCWE-863 | Высокая7,5 | — | 2,2 % | 29 нояб. 2024 г. |
31Наблюдать | CVE-2020-9272Эксплойта нет | ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.proftpd · proftpd · CWE-125 | Высокая7,5 | — | 2,1 % | 20 февр. 2020 г. |
30Наблюдать | CVE-2010-4652Эксплойта нет | Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows rproftpd · proftpd · CWE-119 | Средняя6,8 | — | 11,2 % | 1 февр. 2011 г. |
30Наблюдать | CVE-2010-3867Proof of concept | Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to createproftpd · proftpd · CWE-22 | Высокая7,1 | — | 7,6 % | 9 нояб. 2010 г. |
30Наблюдать | CVE-2021-46854Эксплойта нет | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.proftpd · proftpd · CWE-401 | Высокая7,5 | — | 1,2 % | 23 нояб. 2022 г. |
30Наблюдать | CVE-2019-19271Эксплойта нет | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.proftpd · proftpd · CWE-295 | Высокая7,5 | — | 1,1 % | 26 нояб. 2019 г. |
30Наблюдать | CVE-2019-19270Эксплойта нет | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.proftpd · proftpd · CWE-295 | Высокая7,5 | — | 1,0 % | 26 нояб. 2019 г. |
30Наблюдать | CVE-2019-19272Эксплойта нет | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.proftpd · proftpd · CWE-476 | Высокая7,5 | — | 0,9 % | 26 нояб. 2019 г. |
30Наблюдать | CVE-2026-53994Эксплойта нет | ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncationproftpd · proftpd · CWE-122 | Высокая7,7 | — | 0,7 % | 18 июл. 2026 г. |
- CVE-2015-330669На этой неделе
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
КритическаяCVSS 10,0Готовый эксплойтEPSS 97 %proftpd · proftpd18 мая 2015 г.
- CVE-2010-422167На этой неделе
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exe
КритическаяCVSS 10,0Готовый эксплойтEPSS 91 %proftpd · proftpd9 нояб. 2010 г.
- CVE-2019-1281556В плане
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without
КритическаяCVSS 9,8Proof of conceptEPSS 58 %proftpd · proftpd19 июл. 2019 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2011-413040В плане
Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via ve
КритическаяCVSS 9,0Эксплойта нетEPSS 13 %proftpd · proftpd6 дек. 2011 г.
- CVE-2020-927339Наблюдать
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.
ВысокаяCVSS 8,8Proof of conceptEPSS 12 %proftpd · proftpd20 февр. 2020 г.
- CVE-2010-2010339Наблюдать
ProFTPD 1.3.3c Backdoor Command Execution
КритическаяCVSS 9,3Готовый эксплойтEPSS 5 %proftpd · proftpd20 авг. 2025 г.
- CVE-2019-1821736Наблюдать
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c
ВысокаяCVSS 7,5Proof of conceptEPSS 20 %proftpd · proftpd21 окт. 2019 г.
- CVE-2026-4216734Наблюдать
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of US
ВысокаяCVSS 8,1Proof of conceptEPSS 7 %proftpd · proftpd28 апр. 2026 г.
- CVE-2026-6309034Наблюдать
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %proftpd · proftpd20 июл. 2026 г.
- CVE-2026-3502534Наблюдать
ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %proftpd · proftpd24 июн. 2026 г.
- CVE-2001-013633Наблюдать
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman
СредняяCVSS 5,0Proof of conceptEPSS 45 %proftpd · proftpd12 мар. 2001 г.
- CVE-2004-034633Наблюдать
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte
ВысокаяCVSS 7,8Эксплойта нетEPSS 6 %proftpd · proftpd23 нояб. 2004 г.
- CVE-2009-054332Наблюдать
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded m
СредняяCVSS 6,8Proof of conceptEPSS 16 %proftpd · proftpd12 февр. 2009 г.
- CVE-2016-312532Наблюдать
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cau
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %proftpd · proftpd5 апр. 2016 г.
- CVE-2023-5171331Наблюдать
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backsla
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %proftpd · proftpd21 дек. 2023 г.
- CVE-2024-4865131Наблюдать
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplement
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %29 нояб. 2024 г.
- CVE-2020-927231Наблюдать
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %proftpd · proftpd20 февр. 2020 г.
- CVE-2010-465230Наблюдать
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows r
СредняяCVSS 6,8Эксплойта нетEPSS 11 %proftpd · proftpd1 февр. 2011 г.
- CVE-2010-386730Наблюдать
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create
ВысокаяCVSS 7,1Proof of conceptEPSS 8 %proftpd · proftpd9 нояб. 2010 г.
- CVE-2021-4685430Наблюдать
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %proftpd · proftpd23 нояб. 2022 г.
- CVE-2019-1927130Наблюдать
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %proftpd · proftpd26 нояб. 2019 г.
- CVE-2019-1927030Наблюдать
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %proftpd · proftpd26 нояб. 2019 г.
- CVE-2019-1927230Наблюдать
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %proftpd · proftpd26 нояб. 2019 г.
- CVE-2026-5399430Наблюдать
ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %proftpd · proftpd18 июл. 2026 г.