VYPR

Core FTP Lite

by Coreftp

CVEs (6)

  • CVE-2018-12113CriJul 5, 2018
    risk 0.64cvss 9.8epss 0.07

    Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.

  • CVE-2020-37155HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without…

  • CVE-2014-4643Jun 25, 2014
    risk 0.04cvss epss 0.09

    Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or…

  • CVE-2009-3484Sep 30, 2009
    risk 0.03cvss epss 0.06

    Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information.

  • CVE-2013-3930Apr 4, 2014
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a CWD command reply.

  • CVE-2013-0130Mar 29, 2013
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (application crash) via a long directory name in a (1) DELE, (2) LIST, or (3) VIEW command.