Critical severity9.8NVD Advisory· Published Aug 5, 2025· Updated Jun 16, 2026
CVE-2012-10023
CVE-2012-10023
Description
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:freefloat:freefloat_ftp_server:1.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:freefloat:freefloat_ftp_server:1.0:*:*:*:*:*:*:*
- (no CPE)range: = 1.0.0
- (no CPE)range: *
Patches
Vulnerability mechanics
References
7- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/freefloatftp_user.rbnvdExploit
- www.exploit-db.com/exploits/15689nvdExploit
- www.exploit-db.com/exploits/23243nvdExploit
- my.saintcorporation.com/cgi-bin/exploit_info/freefloat_ftp_server_user_cmdnvdThird Party Advisory
- web.archive.org/web/20101208040029/http://secunia.com/advisories/42465/nvdThird Party Advisory
- www.vulncheck.com/advisories/freefloat-ftp-server-user-command-buffer-overflownvdThird Party Advisory
- web.archive.org/web/20101213050627/http://www.freefloat.com/sv/about-/about-.phpnvdProduct
News mentions
0No linked articles in our index yet.