Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2023-45198
Disclosure Date: October 05, 2023 (last updated October 12, 2023)
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
0
Attacker Value
Unknown
CVE-2015-5917
Disclosure Date: October 09, 2015 (last updated October 05, 2023)
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.
0
Attacker Value
Unknown
CVE-2008-7016
Disclosure Date: August 21, 2009 (last updated October 04, 2023)
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
0
Attacker Value
Unknown
CVE-2004-0794
Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
0