Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2025-1207

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2023-0887

Disclosure Date: February 17, 2023 (last updated February 24, 2025)
A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The associated identifier of this vulnerability is VDB-221351.
Attacker Value
Unknown

CVE-2013-6809

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.
0
Attacker Value
Unknown

CVE-2005-4883

Disclosure Date: November 20, 2009 (last updated October 04, 2023)
Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames."
0
Attacker Value
Unknown

CVE-2005-4882

Disclosure Date: November 20, 2009 (last updated October 04, 2023)
tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.
0
Attacker Value
Unknown

CVE-2008-1403

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename.
0
Attacker Value
Unknown

CVE-2007-2639

Disclosure Date: May 13, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-1404

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.
0
Attacker Value
Unknown

CVE-2006-6141

Disclosure Date: November 28, 2006 (last updated October 04, 2023)
Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window.
0
Attacker Value
Unknown

CVE-2006-4948

Disclosure Date: September 23, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0