Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-22899

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Attacker Value
Unknown

CVE-2020-19595

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
Attacker Value
Unknown

CVE-2020-19596

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
Attacker Value
Unknown

CVE-2020-21588

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
Attacker Value
Unknown

CVE-2020-9488

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Attacker Value
Unknown

CVE-2019-9649

Disclosure Date: March 22, 2019 (last updated November 27, 2024)
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
0
Attacker Value
Unknown

CVE-2019-9648

Disclosure Date: March 22, 2019 (last updated November 27, 2024)
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
0
Attacker Value
Unknown

CVE-2018-20658

Disclosure Date: January 02, 2019 (last updated November 27, 2024)
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
0
Attacker Value
Unknown

CVE-2018-12113

Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
0