VYPR
Vendor

Hfiref0x

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2017-1000218CriNov 17, 2017
    risk 0.64cvss 9.8epss 0.03

    LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.

  • CVE-2024-11144HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file…

  • CVE-2023-24042HigJan 21, 2023
    risk 0.49cvss 7.5epss 0.01

    A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.

  • CVE-2025-65403MedDec 1, 2025
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-70637MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker…