CVE-2010-20103
- EPSS 1.61%
- Veröffentlicht 20.08.2025 15:38:46
- Zuletzt bearbeitet 24.09.2025 17:02:12
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shel...
CVE-2024-57392
- EPSS 1.04%
- Veröffentlicht 06.02.2025 22:15:39
- Zuletzt bearbeitet 02.03.2025 22:15:34
Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.
CVE-2024-48651
- EPSS 0.61%
- Veröffentlicht 29.11.2024 05:15:05
- Zuletzt bearbeitet 17.03.2025 17:15:32
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
CVE-2023-51713
- EPSS 0.54%
- Veröffentlicht 22.12.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:38:39
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
CVE-2023-48795
- EPSS 64.06%
- Veröffentlicht 18.12.2023 16:15:10
- Zuletzt bearbeitet 29.09.2025 21:56:10
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2021-46854
- EPSS 1.12%
- Veröffentlicht 23.11.2022 07:15:09
- Zuletzt bearbeitet 28.04.2025 21:15:55
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
- EPSS 52.27%
- Veröffentlicht 20.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:19
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
CVE-2020-9272
- EPSS 0.77%
- Veröffentlicht 20.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:19
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
CVE-2019-19269
- EPSS 1.78%
- Veröffentlicht 30.11.2019 23:15:18
- Zuletzt bearbeitet 21.11.2024 04:34:27
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrato...
CVE-2019-19272
- EPSS 0.42%
- Veröffentlicht 26.11.2019 04:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:28
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutu...