Medium severity6.2NVD Advisory· Published Apr 5, 2026· Updated Apr 9, 2026
CVE-2019-25683
CVE-2019-25683
Description
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.
Affected products
1- cpe:2.3:a:filezilla-project:filezilla_client:3.40.0:-:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/46484nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/filezilla-denial-of-service-via-local-searchnvdThird Party Advisory
- filezilla-project.orgnvdProduct
News mentions
0No linked articles in our index yet.