proftpd kayıtları
proftpd üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %8,8
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %85,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-295 Improper Certificate Validation2
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-189 Numeric Errors2
- CWE-125 Out-of-bounds Read2
- CWE-399 Resource Management Errors2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
69Bu hafta | CVE-2015-3306Silahlaştırılmış | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.proftpd · proftpd · CWE-284 | Kritik10,0 | — | %96,8 | 18 May 2015 |
67Bu hafta | CVE-2010-4221Silahlaştırılmış | Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exeproftpd · proftpd · CWE-119 | Kritik10,0 | — | %91,3 | 9 Kas 2010 |
56Planlayın | CVE-2019-12815Kavram kanıtı | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure withoutproftpd · proftpd · CWE-755 | Kritik9,8 | — | %57,6 | 19 Tem 2019 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
40Planlayın | CVE-2011-4130İstismar yok | Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via veproftpd · proftpd · CWE-399 | Kritik9,0 | — | %12,6 | 6 Ara 2011 |
39İzleyin | CVE-2020-9273Kavram kanıtı | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.proftpd · proftpd · CWE-416 | Yüksek8,8 | — | %12,0 | 20 Şub 2020 |
39İzleyin | CVE-2010-20103Silahlaştırılmış | ProFTPD 1.3.3c Backdoor Command Executionproftpd · proftpd · CWE-912 | Kritik9,3 | — | %5,1 | 20 Ağu 2025 |
36İzleyin | CVE-2019-18217Kavram kanıtı | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long cproftpd · proftpd · CWE-835 | Yüksek7,5 | — | %20,3 | 21 Eki 2019 |
34İzleyin | CVE-2026-42167Kavram kanıtı | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USproftpd · proftpd · CWE-89 | Yüksek8,1 | — | %7,3 | 28 Nis 2026 |
34İzleyin | CVE-2026-63090İstismar yok | ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassemblyproftpd · proftpd · CWE-122 | Yüksek8,7 | — | %0,9 | 20 Tem 2026 |
34İzleyin | CVE-2026-35025İstismar yok | ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFRproftpd · proftpd · CWE-59 | Yüksek8,6 | — | %0,5 | 24 Haz 2026 |
33İzleyin | CVE-2001-0136Kavram kanıtı | Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commanproftpd · proftpd · CWE-401 | Orta5,0 | — | %44,9 | 12 Mar 2001 |
33İzleyin | CVE-2004-0346İstismar yok | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte proftpd · proftpd · CWE-193 | Yüksek7,8 | — | %5,7 | 23 Kas 2004 |
32İzleyin | CVE-2009-0543Kavram kanıtı | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded mproftpd · proftpd · CWE-89 | Orta6,8 | — | %15,8 | 12 Şub 2009 |
32İzleyin | CVE-2016-3125İstismar yok | The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cauproftpd · proftpd · CWE-254 | Yüksek7,5 | — | %7,0 | 5 Nis 2016 |
31İzleyin | CVE-2023-51713Kavram kanıtı | make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslaproftpd · proftpd · CWE-125 | Yüksek7,5 | — | %4,2 | 21 Ara 2023 |
31İzleyin | CVE-2024-48651Kavram kanıtı | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplementCWE-863 | Yüksek7,5 | — | %2,2 | 29 Kas 2024 |
31İzleyin | CVE-2020-9272İstismar yok | ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.proftpd · proftpd · CWE-125 | Yüksek7,5 | — | %2,1 | 20 Şub 2020 |
30İzleyin | CVE-2010-4652İstismar yok | Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows rproftpd · proftpd · CWE-119 | Orta6,8 | — | %11,2 | 1 Şub 2011 |
30İzleyin | CVE-2010-3867Kavram kanıtı | Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to createproftpd · proftpd · CWE-22 | Yüksek7,1 | — | %7,6 | 9 Kas 2010 |
30İzleyin | CVE-2021-46854İstismar yok | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.proftpd · proftpd · CWE-401 | Yüksek7,5 | — | %1,2 | 23 Kas 2022 |
30İzleyin | CVE-2019-19271İstismar yok | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.proftpd · proftpd · CWE-295 | Yüksek7,5 | — | %1,1 | 26 Kas 2019 |
30İzleyin | CVE-2019-19270İstismar yok | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.proftpd · proftpd · CWE-295 | Yüksek7,5 | — | %1,0 | 26 Kas 2019 |
30İzleyin | CVE-2019-19272İstismar yok | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.proftpd · proftpd · CWE-476 | Yüksek7,5 | — | %0,9 | 26 Kas 2019 |
30İzleyin | CVE-2026-53994İstismar yok | ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncationproftpd · proftpd · CWE-122 | Yüksek7,7 | — | %0,7 | 18 Tem 2026 |
- CVE-2015-330669Bu hafta
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
KritikCVSS 10,0SilahlaştırılmışEPSS %97proftpd · proftpd18 May 2015
- CVE-2010-422167Bu hafta
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to exe
KritikCVSS 10,0SilahlaştırılmışEPSS %91proftpd · proftpd9 Kas 2010
- CVE-2019-1281556Planlayın
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without
KritikCVSS 9,8Kavram kanıtıEPSS %58proftpd · proftpd19 Tem 2019
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2011-413040Planlayın
Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via ve
KritikCVSS 9,0İstismar yokEPSS %13proftpd · proftpd6 Ara 2011
- CVE-2020-927339İzleyin
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.
YüksekCVSS 8,8Kavram kanıtıEPSS %12proftpd · proftpd20 Şub 2020
- CVE-2010-2010339İzleyin
ProFTPD 1.3.3c Backdoor Command Execution
KritikCVSS 9,3SilahlaştırılmışEPSS %5proftpd · proftpd20 Ağu 2025
- CVE-2019-1821736İzleyin
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long c
YüksekCVSS 7,5Kavram kanıtıEPSS %20proftpd · proftpd21 Eki 2019
- CVE-2026-4216734İzleyin
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of US
YüksekCVSS 8,1Kavram kanıtıEPSS %7proftpd · proftpd28 Nis 2026
- CVE-2026-6309034İzleyin
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
YüksekCVSS 8,7İstismar yokEPSS %1proftpd · proftpd20 Tem 2026
- CVE-2026-3502534İzleyin
ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
YüksekCVSS 8,6İstismar yokEPSS %1proftpd · proftpd24 Haz 2026
- CVE-2001-013633İzleyin
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman
OrtaCVSS 5,0Kavram kanıtıEPSS %45proftpd · proftpd12 Mar 2001
- CVE-2004-034633İzleyin
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte
YüksekCVSS 7,8İstismar yokEPSS %6proftpd · proftpd23 Kas 2004
- CVE-2009-054332İzleyin
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded m
OrtaCVSS 6,8Kavram kanıtıEPSS %16proftpd · proftpd12 Şub 2009
- CVE-2016-312532İzleyin
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cau
YüksekCVSS 7,5İstismar yokEPSS %7proftpd · proftpd5 Nis 2016
- CVE-2023-5171331İzleyin
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backsla
YüksekCVSS 7,5Kavram kanıtıEPSS %4proftpd · proftpd21 Ara 2023
- CVE-2024-4865131İzleyin
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplement
YüksekCVSS 7,5Kavram kanıtıEPSS %229 Kas 2024
- CVE-2020-927231İzleyin
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
YüksekCVSS 7,5İstismar yokEPSS %2proftpd · proftpd20 Şub 2020
- CVE-2010-465230İzleyin
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows r
OrtaCVSS 6,8İstismar yokEPSS %11proftpd · proftpd1 Şub 2011
- CVE-2010-386730İzleyin
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create
YüksekCVSS 7,1Kavram kanıtıEPSS %8proftpd · proftpd9 Kas 2010
- CVE-2021-4685430İzleyin
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
YüksekCVSS 7,5İstismar yokEPSS %1proftpd · proftpd23 Kas 2022
- CVE-2019-1927130İzleyin
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
YüksekCVSS 7,5İstismar yokEPSS %1proftpd · proftpd26 Kas 2019
- CVE-2019-1927030İzleyin
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.
YüksekCVSS 7,5İstismar yokEPSS %1proftpd · proftpd26 Kas 2019
- CVE-2019-1927230İzleyin
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
YüksekCVSS 7,5İstismar yokEPSS %1proftpd · proftpd26 Kas 2019
- CVE-2026-5399430İzleyin
ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation
YüksekCVSS 7,7İstismar yokEPSS %1proftpd · proftpd18 Tem 2026