Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown

CVE-2004-1992

Disclosure Date: April 20, 2004 (last updated February 22, 2025)
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2002-2393

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.
0
Attacker Value
Unknown

CVE-2001-1463

Disclosure Date: November 19, 2001 (last updated February 22, 2025)
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
0
Attacker Value
Unknown

CVE-2001-0054

Disclosure Date: February 16, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
0
Attacker Value
Unknown

CVE-2000-1033

Disclosure Date: December 11, 2000 (last updated February 22, 2025)
Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.
0
Attacker Value
Unknown

CVE-2000-0837

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes.
0
Attacker Value
Unknown

CVE-2000-0786

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.
0
Attacker Value
Unknown

CVE-2000-0176

Disclosure Date: February 29, 2000 (last updated February 22, 2025)
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
0
Attacker Value
Unknown

CVE-1999-0838

Disclosure Date: December 01, 1999 (last updated February 22, 2025)
Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.
0
Attacker Value
Unknown

CVE-1999-0219

Disclosure Date: July 01, 1997 (last updated February 22, 2025)
Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
0