Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2021-30047

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
Attacker Value
Unknown

CVE-2021-3618

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Attacker Value
Unknown

CVE-2011-2523

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
Attacker Value
Unknown

CVE-2015-1419

Disclosure Date: January 28, 2015 (last updated July 18, 2024)
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.
0
Attacker Value
Unknown

CVE-2011-0762

Disclosure Date: March 02, 2011 (last updated October 04, 2023)
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
0
Attacker Value
Unknown

CVE-2009-4457

Disclosure Date: December 30, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."
0
Attacker Value
Unknown

CVE-2008-2375

Disclosure Date: July 09, 2008 (last updated October 04, 2023)
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than CVE-2007-5962.
0
Attacker Value
Unknown

CVE-2004-2259

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant.
0
Attacker Value
Unknown

CVE-2004-0042

Disclosure Date: February 03, 2004 (last updated February 22, 2025)
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
0