ProFTPD Project kayıtları
proftpd project üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %5,3
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %52,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2006-5815Silahlaştırılmış | Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause proftpd project · proftpd · CWE-119 | Kritik10,0 | — | %75,5 | 8 Kas 2006 |
54Planlayın | CVE-2003-0831Kavram kanıtı | ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attproftpd project · proftpd · CWE-119 | Kritik9,0 | — | %58,4 | 17 Kas 2003 |
52Planlayın | CVE-2009-0542Kavram kanıtı | SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (peproftpd project · proftpd · CWE-89 | Yüksek7,5 | — | %73,8 | 12 Şub 2009 |
52Planlayın | CVE-1999-0368Kavram kanıtı | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.proftpd project · proftpd | Kritik10,0 | — | %39,8 | 9 Şub 1999 |
51Planlayın | CVE-1999-0911Kavram kanıtı | Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that creaproftpd project · proftpd | Kritik10,0 | — | %38,1 | 27 Ağu 1999 |
45Planlayın | CVE-2003-0500Kavram kanıtı | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers tproftpd project · proftpd | Kritik10,0 | — | %18,3 | 7 Ağu 2003 |
35İzleyin | CVE-2006-6170İstismar yok | Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other produproftpd project · proftpd | Yüksek7,5 | — | %17,1 | 30 Kas 2006 |
34İzleyin | CVE-2005-4816İstismar yok | Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute aproftpd project · proftpd | Yüksek7,5 | — | %12,8 | 31 Ara 2005 |
34İzleyin | CVE-2001-1500İstismar yok | ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which aproftpd project · proftpd | Yüksek7,5 | — | %12,4 | 31 Ara 2001 |
33İzleyin | CVE-2001-0318İstismar yok | Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while usinproftpd project · proftpd | Yüksek7,5 | — | %11,4 | 2 Haz 2001 |
33İzleyin | CVE-2006-6171İstismar yok | ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which proftpd project · proftpd | Yüksek7,5 | — | %9,7 | 30 Kas 2006 |
33İzleyin | CVE-2004-0432İstismar yok | ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypproftpd project · proftpd | Yüksek7,5 | — | %9,2 | 18 Ağu 2004 |
32İzleyin | CVE-2001-1501Kavram kanıtı | The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory coproftpd project · proftpd | Orta5,0 | — | %38,4 | 31 Ara 2001 |
32İzleyin | CVE-2001-0027İstismar yok | mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticaproftpd project · proftpd | Yüksek7,5 | — | %6,5 | 12 Şub 2001 |
29İzleyin | CVE-2008-4242İstismar yok | ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request proftpd project · proftpd · CWE-352 | Orta6,8 | — | %7,1 | 25 Eyl 2008 |
28İzleyin | CVE-2005-2390İstismar yok | Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive informatiproftpd project · proftpd | Orta6,4 | — | %9,2 | 27 Tem 2005 |
27İzleyin | CVE-2006-6563Kavram kanıtı | Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows localproftpd project · proftpd | Orta6,6 | — | %2,3 | 15 Ara 2006 |
24İzleyin | CVE-2007-2165İstismar yok | The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module proftpd project · proftpd | Orta5,1 | — | %12,2 | 22 Nis 2007 |
19İzleyin | CVE-1999-1475İstismar yok | ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwordsproftpd project · proftpd | Orta4,6 | — | %4,4 | 19 Kas 1999 |
- CVE-2006-581563Bu hafta
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause
KritikCVSS 10,0SilahlaştırılmışEPSS %75proftpd project · proftpd8 Kas 2006
- CVE-2003-083154Planlayın
ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote att
KritikCVSS 9,0Kavram kanıtıEPSS %58proftpd project · proftpd17 Kas 2003
- CVE-2009-054252Planlayın
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (pe
YüksekCVSS 7,5Kavram kanıtıEPSS %74proftpd project · proftpd12 Şub 2009
- CVE-1999-036852Planlayın
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.
KritikCVSS 10,0Kavram kanıtıEPSS %40proftpd project · proftpd9 Şub 1999
- CVE-1999-091151Planlayın
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that crea
KritikCVSS 10,0Kavram kanıtıEPSS %38proftpd project · proftpd27 Ağu 1999
- CVE-2003-050045Planlayın
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers t
KritikCVSS 10,0Kavram kanıtıEPSS %18proftpd project · proftpd7 Ağu 2003
- CVE-2006-617035İzleyin
Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other produ
YüksekCVSS 7,5İstismar yokEPSS %17proftpd project · proftpd30 Kas 2006
- CVE-2005-481634İzleyin
Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute a
YüksekCVSS 7,5İstismar yokEPSS %13proftpd project · proftpd31 Ara 2005
- CVE-2001-150034İzleyin
ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which a
YüksekCVSS 7,5İstismar yokEPSS %12proftpd project · proftpd31 Ara 2001
- CVE-2001-031833İzleyin
Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while usin
YüksekCVSS 7,5İstismar yokEPSS %11proftpd project · proftpd2 Haz 2001
- CVE-2006-617133İzleyin
ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which
YüksekCVSS 7,5İstismar yokEPSS %10proftpd project · proftpd30 Kas 2006
- CVE-2004-043233İzleyin
ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to byp
YüksekCVSS 7,5İstismar yokEPSS %9proftpd project · proftpd18 Ağu 2004
- CVE-2001-150132İzleyin
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory co
OrtaCVSS 5,0Kavram kanıtıEPSS %38proftpd project · proftpd31 Ara 2001
- CVE-2001-002732İzleyin
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authentica
YüksekCVSS 7,5İstismar yokEPSS %6proftpd project · proftpd12 Şub 2001
- CVE-2008-424229İzleyin
ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request
OrtaCVSS 6,8İstismar yokEPSS %7proftpd project · proftpd25 Eyl 2008
- CVE-2005-239028İzleyin
Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive informati
OrtaCVSS 6,4İstismar yokEPSS %9proftpd project · proftpd27 Tem 2005
- CVE-2006-656327İzleyin
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local
OrtaCVSS 6,6Kavram kanıtıEPSS %2proftpd project · proftpd15 Ara 2006
- CVE-2007-216524İzleyin
The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module
OrtaCVSS 5,1İstismar yokEPSS %12proftpd project · proftpd22 Nis 2007
- CVE-1999-147519İzleyin
ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords
OrtaCVSS 4,6İstismar yokEPSS %4proftpd project · proftpd19 Kas 1999