Proftpd

Proftpd

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 57.61%
  • Veröffentlicht 19.07.2019 23:15:11
  • Zuletzt bearbeitet 04.11.2025 16:15:42

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.

  • EPSS 0.42%
  • Veröffentlicht 04.04.2017 17:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlin...

  • EPSS 6.98%
  • Veröffentlicht 05.04.2016 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecif...

Exploit
  • EPSS 96.8%
  • Veröffentlicht 18.05.2015 15:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Exploit
  • EPSS 2.99%
  • Veröffentlicht 30.09.2013 21:55:07
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.

  • EPSS 0.69%
  • Veröffentlicht 24.01.2013 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.

Exploit
  • EPSS 12.63%
  • Veröffentlicht 06.12.2011 11:55:06
  • Zuletzt bearbeitet 16.06.2026 23:34:28

Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.

Exploit
  • EPSS 28.07%
  • Veröffentlicht 11.03.2011 17:55:03
  • Zuletzt bearbeitet 16.06.2026 23:28:47

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.

Exploit
  • EPSS 11.34%
  • Veröffentlicht 02.02.2011 01:00:04
  • Zuletzt bearbeitet 16.06.2026 23:25:15

Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted usernam...

Exploit
  • EPSS 91.3%
  • Veröffentlicht 09.11.2010 21:00:06
  • Zuletzt bearbeitet 16.06.2026 23:24:23

Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.