Vendor CVEs
Proftpd
All CVEs
58 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0027 | 0.01 | — | 0.06 | Feb 12, 2001 | mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users. | |||
| CVE-2021-46854 | Hig | 0.00 | 7.5 | 0.01 | Nov 23, 2022 | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters. | ||
| CVE-2013-4359 | 0.00 | — | 0.03 | Sep 30, 2013 | Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation. | |||
| CVE-2012-6095 | 0.00 | — | 0.01 | Jan 24, 2013 | ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands. | |||
| CVE-2008-7265 | 0.00 | — | 0.03 | Nov 9, 2010 | The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer. | |||
| CVE-2009-3639 | 0.00 | — | 0.06 | Oct 28, 2009 | The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers… | |||
| CVE-2001-0456 | 0.00 | — | 0.06 | Jun 27, 2001 | postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended. | |||
| CVE-1999-1475 | 0.00 | — | 0.04 | Nov 19, 1999 | ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command. |
- CVE-2001-0027Feb 12, 2001risk 0.01cvss —epss 0.06
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.
- risk 0.00cvss 7.5epss 0.01
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
- CVE-2013-4359Sep 30, 2013risk 0.00cvss —epss 0.03
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
- CVE-2012-6095Jan 24, 2013risk 0.00cvss —epss 0.01
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
- CVE-2008-7265Nov 9, 2010risk 0.00cvss —epss 0.03
The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.
- CVE-2009-3639Oct 28, 2009risk 0.00cvss —epss 0.06
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers…
- CVE-2001-0456Jun 27, 2001risk 0.00cvss —epss 0.06
postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.
- CVE-1999-1475Nov 19, 1999risk 0.00cvss —epss 0.04
ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.
Page 2 of 2