Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Proftpd HIGH 7.5
CVE-2009-0542EPSS 77%

SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) ch…

No fix yet
Fix from $1,950 2009-02-12
Proftpd MEDIUM 6.8
CVE-2008-4242EPSS 7%

ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (…

No fix yet
Fix from $1,600 2008-09-25
Proftpd MEDIUM 5.1
CVE-2007-2165EPSS 12%

The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that chec…

Fix: after 1.3.0_rc1
Fix from $1,600 2007-04-22
Proftpd MEDIUM 6.6
CVE-2006-6563

Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to…

Patch available
Fix from $1,600 2006-12-15
Proftpd HIGH 7.5
CVE-2006-6170EPSS 17%

Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allo…

Fix: after 1.3.0a
Fix from $1,950 2006-11-30
Proftpd HIGH 7.5
CVE-2006-6171EPSS 10%

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to …

Fix: after 1.3.0a
Fix from $1,950 2006-11-30
Proftpd HIGH 10.0
CVE-2006-5815EPSS 74%

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial …

Fix: after 1.3.0
Fix from $1,950 2006-11-08
Proftpd HIGH 7.5
CVE-2005-4816EPSS 13%

Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …

Patch available
Fix from $1,950 2005-12-31
Proftpd MEDIUM 6.4
CVE-2005-2390EPSS 9%

Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1…

Mitigation only
Fix from $1,600 2005-07-27
Proftpd HIGH 9.0
CVE-2003-0831EPSS 58%

ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to…

No fix yet
Fix from $1,950 2003-11-17
Proftpd HIGH 10.0
CVE-2003-0500EPSS 18%

SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute…

Patch available
Fix from $1,950 2003-08-07
Proftpd HIGH 7.5
CVE-2001-1500EPSS 12%

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows rem…

Patch available
Fix from $1,950 2001-12-31
Proftpd MEDIUM 5.0
CVE-2001-1501EPSS 38%

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption…

Mitigation only
Fix from $1,600 2001-12-31
Proftpd HIGH 7.5
CVE-2001-0318EPSS 11%

Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malfo…

Patch available
Fix from $1,950 2001-06-02
Proftpd HIGH 7.5
CVE-2001-0027EPSS 6%

mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attac…

No fix yet
Fix from $1,950 2001-02-12
Proftpd HIGH 10.0
CVE-1999-0911EPSS 38%

Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested…

Mitigation only
Fix from $1,950 1999-08-27