İçeriğe atla
Noroxi

ProFTPD Project kayıtları

proftpd project üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %5,3
Pre-auth RCE
7
Düzeltme kaydı olan
%52,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2006-5815
    63Bu hafta

    Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause

    KritikCVSS 10,0SilahlaştırılmışEPSS %75

    proftpd project · proftpd8 Kas 2006

  • CVE-2003-0831
    54Planlayın

    ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote att

    KritikCVSS 9,0Kavram kanıtıEPSS %58

    proftpd project · proftpd17 Kas 2003

  • CVE-2009-0542
    52Planlayın

    SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (pe

    YüksekCVSS 7,5Kavram kanıtıEPSS %74

    proftpd project · proftpd12 Şub 2009

  • CVE-1999-0368
    52Planlayın

    Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.

    KritikCVSS 10,0Kavram kanıtıEPSS %40

    proftpd project · proftpd9 Şub 1999

  • CVE-1999-0911
    51Planlayın

    Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that crea

    KritikCVSS 10,0Kavram kanıtıEPSS %38

    proftpd project · proftpd27 Ağu 1999

  • CVE-2003-0500
    45Planlayın

    SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers t

    KritikCVSS 10,0Kavram kanıtıEPSS %18

    proftpd project · proftpd7 Ağu 2003

  • CVE-2006-6170
    35İzleyin

    Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other produ

    YüksekCVSS 7,5İstismar yokEPSS %17

    proftpd project · proftpd30 Kas 2006

  • CVE-2005-4816
    34İzleyin

    Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute a

    YüksekCVSS 7,5İstismar yokEPSS %13

    proftpd project · proftpd31 Ara 2005

  • CVE-2001-1500
    34İzleyin

    ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which a

    YüksekCVSS 7,5İstismar yokEPSS %12

    proftpd project · proftpd31 Ara 2001

  • CVE-2001-0318
    33İzleyin

    Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while usin

    YüksekCVSS 7,5İstismar yokEPSS %11

    proftpd project · proftpd2 Haz 2001

  • CVE-2006-6171
    33İzleyin

    ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which

    YüksekCVSS 7,5İstismar yokEPSS %10

    proftpd project · proftpd30 Kas 2006

  • CVE-2004-0432
    33İzleyin

    ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to byp

    YüksekCVSS 7,5İstismar yokEPSS %9

    proftpd project · proftpd18 Ağu 2004

  • CVE-2001-1501
    32İzleyin

    The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory co

    OrtaCVSS 5,0Kavram kanıtıEPSS %38

    proftpd project · proftpd31 Ara 2001

  • CVE-2001-0027
    32İzleyin

    mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authentica

    YüksekCVSS 7,5İstismar yokEPSS %6

    proftpd project · proftpd12 Şub 2001

  • CVE-2008-4242
    29İzleyin

    ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request

    OrtaCVSS 6,8İstismar yokEPSS %7

    proftpd project · proftpd25 Eyl 2008

  • CVE-2005-2390
    28İzleyin

    Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive informati

    OrtaCVSS 6,4İstismar yokEPSS %9

    proftpd project · proftpd27 Tem 2005

  • CVE-2006-6563
    27İzleyin

    Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local

    OrtaCVSS 6,6Kavram kanıtıEPSS %2

    proftpd project · proftpd15 Ara 2006

  • CVE-2007-2165
    24İzleyin

    The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module

    OrtaCVSS 5,1İstismar yokEPSS %12

    proftpd project · proftpd22 Nis 2007

  • CVE-1999-1475
    19İzleyin

    ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords

    OrtaCVSS 4,6İstismar yokEPSS %4

    proftpd project · proftpd19 Kas 1999