CVE-2019-25686
- EPSS 0.16%
- Veröffentlicht 05.04.2026 20:45:35
- Zuletzt bearbeitet 09.04.2026 19:03:17
Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload...
CVE-2019-25654
- EPSS 0.05%
- Veröffentlicht 30.03.2026 11:02:27
- Zuletzt bearbeitet 08.04.2026 16:18:03
Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into ...
CVE-2022-22899
- EPSS 0.18%
- Veröffentlicht 17.02.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:36
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
CVE-2022-22836
- EPSS 3.13%
- Veröffentlicht 10.01.2022 14:12:57
- Zuletzt bearbeitet 21.11.2024 06:47:33
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
CVE-2020-19596
- EPSS 0.46%
- Veröffentlicht 05.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:15
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
CVE-2020-19595
- EPSS 0.35%
- Veröffentlicht 05.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:15
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
CVE-2020-21588
- EPSS 0.05%
- Veröffentlicht 02.04.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:12:42
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
CVE-2019-9649
- EPSS 28.94%
- Veröffentlicht 22.03.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:03
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file o...
CVE-2019-9648
- EPSS 19.73%
- Veröffentlicht 22.03.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:02
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned i...
CVE-2018-20658
- EPSS 19.82%
- Veröffentlicht 02.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:56
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.