Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2020-6835

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
Attacker Value
Unknown

CVE-2020-6162

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.
Attacker Value
Unknown

CVE-2017-16892

Disclosure Date: November 19, 2017 (last updated November 26, 2024)
In Bftpd before 4.7, there is a memory leak in the file rename function.
0
Attacker Value
Unknown

CVE-2009-4593

Disclosure Date: January 07, 2010 (last updated October 04, 2023)
The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-5184

Disclosure Date: October 03, 2007 (last updated October 04, 2023)
Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.
0
Attacker Value
Unknown

CVE-2007-2051

Disclosure Date: April 16, 2007 (last updated October 04, 2023)
Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable.
0
Attacker Value
Unknown

CVE-2007-2010

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.
0
Attacker Value
Unknown

CVE-2001-0065

Disclosure Date: February 12, 2001 (last updated February 22, 2025)
Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.
0
Attacker Value
Unknown

CVE-2000-0943

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.
0