VYPR
Vendor

LightFTP

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2017-1000218CriNov 17, 2017
    risk 0.64cvss 9.8epss 0.03

    LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.

  • CVE-2024-11144HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file…

  • CVE-2023-24042HigJan 21, 2023
    risk 0.49cvss 7.5epss 0.01

    A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.

  • CVE-2025-65403MedDec 1, 2025
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-67607MedJul 31, 2026
    risk 0.00cvss 5.9epss 0.00

    LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to…