Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2012-6095
Disclosure Date: January 24, 2013 (last updated October 05, 2023)
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
0
Attacker Value
Unknown
CVE-2011-4130
Disclosure Date: December 06, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.
0
Attacker Value
Unknown
CVE-2011-1137
Disclosure Date: March 11, 2011 (last updated October 04, 2023)
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.
0
Attacker Value
Unknown
CVE-2010-4652
Disclosure Date: February 02, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
0
Attacker Value
Unknown
CVE-2010-3867
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modify file timestamps via directory traversal sequences in a (1) SITE MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE UTIME command.
0
Attacker Value
Unknown
CVE-2008-7265
Disclosure Date: November 09, 2010 (last updated October 04, 2023)
The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.
0
Attacker Value
Unknown
CVE-2005-4816
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.
0
Attacker Value
Unknown
CVE-2005-2390
Disclosure Date: July 27, 2005 (last updated February 22, 2025)
Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive.
0
Attacker Value
Unknown
CVE-2001-1501
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.
0
Attacker Value
Unknown
CVE-2001-1500
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.
0