Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2020-6835
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
0
Attacker Value
Unknown
CVE-2020-6162
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.
0
Attacker Value
Unknown
CVE-2017-16892
Disclosure Date: November 19, 2017 (last updated November 26, 2024)
In Bftpd before 4.7, there is a memory leak in the file rename function.
0
Attacker Value
Unknown
CVE-2009-4593
Disclosure Date: January 07, 2010 (last updated October 04, 2023)
The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-5184
Disclosure Date: October 03, 2007 (last updated October 04, 2023)
Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.
0
Attacker Value
Unknown
CVE-2007-2051
Disclosure Date: April 16, 2007 (last updated October 04, 2023)
Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable.
0
Attacker Value
Unknown
CVE-2007-2010
Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.
0
Attacker Value
Unknown
CVE-2001-0065
Disclosure Date: February 12, 2001 (last updated February 22, 2025)
Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.
0
Attacker Value
Unknown
CVE-2000-0943
Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.
0