Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Proftpd HIGH 8.8
CVE-2026-63090

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privileg…

Fix: 1.3.9c+
Fix from $1,950 2026-07-20
Proftpd MEDIUM 6.5
CVE-2026-63091

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows auth…

Fix: 1.3.9c+
Fix from $1,600 2026-07-20
Proftpd MEDIUM 6.5
CVE-2026-53994

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-s…

Fix: 1.3.10+
Fix from $1,600 2026-07-18
Proftpd HIGH 8.1
CVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL …

Fix: after 1.3.9b
Fix from $1,950 2026-06-24
Proftpd HIGH 8.1
CVE-2026-42167

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER reques…

Fix: after 1.3.9b
Fix from $1,950 2026-04-28
Proftpd CRITICAL 9.8
CVE-2010-20103EPSS 5%

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor im…

Mitigation only
Fix from $2,300 2025-08-20
Proftpd HIGH 7.5
CVE-2023-51713

make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semant…

Fix: 1.3.8a+
Fix from $1,950 2023-12-22
Proftpd HIGH 7.5
CVE-2021-46854

mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.

Fix: 1.3.7c+
Fix from $1,950 2022-11-23
Proftpd HIGH 7.5
CVE-2020-9272

ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.

Fix: 1.3.6c / 3.0+
Fix from $1,950 2020-02-20
Proftpd HIGH 7.5
CVE-2019-19271

An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL en…

Fix: 1.3.6+
Fix from $1,950 2019-11-26
Proftpd HIGH 7.5
CVE-2019-19272

An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a c…

Fix: 1.3.6+
Fix from $1,950 2019-11-26
Proftpd HIGH 7.5
CVE-2019-18217EPSS 20%

ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands b…

Fix: after 1.3.5
Fix from $1,950 2019-10-21
Proftpd MEDIUM 5.5
CVE-2017-7418

ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSy…

Fix: after 1.3.5
Fix from $1,600 2017-04-04
Proftpd HIGH 10.0
CVE-2015-3306EPSS 97%

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Mitigation only
Fix from $1,950 2015-05-18
Proftpd MEDIUM 5.0
CVE-2013-4359

Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via …

Patch available
Fix from $1,600 2013-09-30
Proftpd HIGH 9.0
CVE-2011-4130EPSS 13%

Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors inv…

Fix: after 1.3.3
Fix from $1,950 2011-12-06
Proftpd MEDIUM 5.0
CVE-2011-1137EPSS 28%

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consump…

Fix: after 1.3.3
Fix from $1,600 2011-03-11
Proftpd MEDIUM 6.8
CVE-2010-4652EPSS 11%

Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote att…

Fix: after 1.3.3
Fix from $1,600 2011-02-02
Proftpd HIGH 10.0
CVE-2010-4221EPSS 91%

Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbi…

No fix yet
Fix from $1,950 2010-11-09
Proftpd HIGH 7.1
CVE-2010-3867EPSS 8%

Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create director…

No fix yet
Fix from $1,950 2010-11-09
Proftpd MEDIUM 5.8
CVE-2009-3639EPSS 6%

The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\…

Fix: after 1.3.2
Fix from $1,600 2009-10-28
Proftpd MEDIUM 6.8
CVE-2009-0543EPSS 19%

ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte …

Mitigation only
Fix from $1,600 2009-02-12
Proftpd HIGH 7.8
CVE-2004-0346EPSS 6%

Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR comm…

Fix: 1.2.9+
Fix from $1,950 2004-11-23
Proftpd MEDIUM 5.0
CVE-2004-1602EPSS 31%

ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to iden…

Fix: after 1.2.10
Fix from $1,600 2004-10-15