VYPR

proftpd-dfsg

by Debian

CVEs (2)

  • CVE-2026-63091Jul 21, 2026
    risk 0.00cvss epss

    ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative…

  • CVE-2026-63090Jul 21, 2026
    risk 0.00cvss epss

    ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in…