Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-45198

Disclosure Date: October 05, 2023 (last updated October 12, 2023)
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
Attacker Value
Unknown

CVE-2015-5917

Disclosure Date: October 09, 2015 (last updated October 05, 2023)
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.
0
Attacker Value
Unknown

CVE-2008-7016

Disclosure Date: August 21, 2009 (last updated October 04, 2023)
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
0
Attacker Value
Unknown

CVE-2004-0794

Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
0