CVE-2010-20103
- EPSS 1.61%
- Published 20.08.2025 15:38:46
- Last modified 24.09.2025 17:02:12
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shel...
CVE-2024-57392
- EPSS 1.04%
- Published 06.02.2025 22:15:39
- Last modified 02.03.2025 22:15:34
Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.
CVE-2024-48651
- EPSS 0.61%
- Published 29.11.2024 05:15:05
- Last modified 17.03.2025 17:15:32
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
CVE-2023-51713
- EPSS 0.54%
- Published 22.12.2023 03:15:09
- Last modified 21.11.2024 08:38:39
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
CVE-2023-48795
- EPSS 64.06%
- Published 18.12.2023 16:15:10
- Last modified 29.09.2025 21:56:10
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2021-46854
- EPSS 1.12%
- Published 23.11.2022 07:15:09
- Last modified 28.04.2025 21:15:55
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
- EPSS 52.27%
- Published 20.02.2020 16:15:11
- Last modified 21.11.2024 05:40:19
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
CVE-2020-9272
- EPSS 0.77%
- Published 20.02.2020 16:15:11
- Last modified 21.11.2024 05:40:19
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
CVE-2019-19269
- EPSS 1.78%
- Published 30.11.2019 23:15:18
- Last modified 21.11.2024 04:34:27
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrato...
CVE-2019-19272
- EPSS 0.42%
- Published 26.11.2019 04:15:13
- Last modified 21.11.2024 04:34:28
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutu...