Hfiref0x

Lightftp

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 06.08.2026 14:15:09
  • Zuletzt bearbeitet 06.08.2026 22:18:28

LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_...

  • EPSS 0.3%
  • Veröffentlicht 31.07.2026 16:17:11
  • Zuletzt bearbeitet 03.08.2026 20:17:28

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 01.12.2025 00:00:00
  • Zuletzt bearbeitet 05.12.2025 21:50:48

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 21.01.2023 02:15:09
  • Zuletzt bearbeitet 08.12.2025 14:59:09

A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.

Exploit
  • EPSS 3.38%
  • Veröffentlicht 17.11.2017 00:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.