Filezilla-Project kayıtları
filezilla-project üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %7,1
- Silahlaştırılmış
- 3 · %21,4
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %42,9
- Yayından KEV’e ortanca
- 2949 gün
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-125 Out-of-bounds Read1
- CWE-20 Improper Input Validation1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2014-0160Silahlaştırılmış | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Yüksek7,5 | KEV | %100,0 | 7 Nis 2014 |
58Planlayın | CVE-2014-0224Silahlaştırılmış | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Yüksek7,4 | — | %95,3 | 5 Haz 2014 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
37İzleyin | CVE-2006-6565Silahlaştırılmış | FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) Nfilezilla-project · filezilla server · CWE-476 | Orta4,0 | — | %70,6 | 15 Ara 2006 |
34İzleyin | CVE-2023-53959İstismar yok | FileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dllfilezilla-project · filezilla client · CWE-427 | Yüksek8,5 | — | %0,9 | 19 Ara 2025 |
32İzleyin | CVE-2019-5429İstismar yok | Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's homfilezilla-project · filezilla client · CWE-426 | Yüksek7,8 | — | %3,0 | 29 Nis 2019 |
31İzleyin | CVE-2016-15003İstismar yok | FileZilla Client Installer uninstall.exe unquoted search pathfilezilla-project · filezilla client · CWE-428 | Yüksek7,8 | — | %0,9 | 18 Tem 2022 |
27İzleyin | CVE-2022-29620İstismar yok | FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does nfilezilla-project · filezilla client · CWE-312 | Orta6,5 | — | %1,9 | 7 Haz 2022 |
27İzleyin | CVE-2019-25683İstismar yok | FileZilla 3.40.0 Denial of Service via Local Searchfilezilla-project · filezilla client · CWE-532 | Orta6,9 | — | %0,2 | 5 Nis 2026 |
25İzleyin | CVE-2024-31497Kavram kanıtı | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quiputty · putty · CWE-338 | Orta5,9 | — | %5,8 | 15 Nis 2024 |
21İzleyin | CVE-2005-0851Kavram kanıtı | FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loopfilezilla-project · filezilla server · CWE-835 | Orta5,0 | — | %2,2 | 2 May 2005 |
21İzleyin | CVE-2005-0850Kavram kanıtı | FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS devfilezilla-project · filezilla server · CWE-20 | Orta5,0 | — | %2,2 | 2 May 2005 |
18İzleyin | CVE-2009-0884Kavram kanıtı | Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSfilezilla-project · filezilla server · CWE-120 | Orta4,3 | — | %3,4 | 12 Mar 2009 |
17İzleyin | CVE-2015-10003İstismar yok | FileZilla Server PORT confused deputyfilezilla-project · filezilla server · CWE-441 | Orta4,3 | — | %0,5 | 17 Tem 2022 |
- CVE-2014-016090Hemen
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100openssl · openssl7 Nis 2014
- CVE-2014-022458Planlayın
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
YüksekCVSS 7,4SilahlaştırılmışEPSS %95openssl · openssl5 Haz 2014
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2006-656537İzleyin
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) N
OrtaCVSS 4,0SilahlaştırılmışEPSS %71filezilla-project · filezilla server15 Ara 2006
- CVE-2023-5395934İzleyin
FileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dll
YüksekCVSS 8,5İstismar yokEPSS %1filezilla-project · filezilla client19 Ara 2025
- CVE-2019-542932İzleyin
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's hom
YüksekCVSS 7,8İstismar yokEPSS %3filezilla-project · filezilla client29 Nis 2019
- CVE-2016-1500331İzleyin
FileZilla Client Installer uninstall.exe unquoted search path
YüksekCVSS 7,8İstismar yokEPSS %1filezilla-project · filezilla client18 Tem 2022
- CVE-2022-2962027İzleyin
FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does n
OrtaCVSS 6,5İstismar yokEPSS %2filezilla-project · filezilla client7 Haz 2022
- CVE-2019-2568327İzleyin
FileZilla 3.40.0 Denial of Service via Local Search
OrtaCVSS 6,9İstismar yokEPSS %0filezilla-project · filezilla client5 Nis 2026
- CVE-2024-3149725İzleyin
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a qui
OrtaCVSS 5,9Kavram kanıtıEPSS %6putty · putty15 Nis 2024
- CVE-2005-085121İzleyin
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop
OrtaCVSS 5,0Kavram kanıtıEPSS %2filezilla-project · filezilla server2 May 2005
- CVE-2005-085021İzleyin
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS dev
OrtaCVSS 5,0Kavram kanıtıEPSS %2filezilla-project · filezilla server2 May 2005
- CVE-2009-088418İzleyin
Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SS
OrtaCVSS 4,3Kavram kanıtıEPSS %3filezilla-project · filezilla server12 Mar 2009
- CVE-2015-1000317İzleyin
FileZilla Server PORT confused deputy
OrtaCVSS 4,3İstismar yokEPSS %1filezilla-project · filezilla server17 Tem 2022