CVE-2022-22899
- EPSS 0.18%
- Veröffentlicht 17.02.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:36
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
CVE-2022-22836
- EPSS 3.13%
- Veröffentlicht 10.01.2022 14:12:57
- Zuletzt bearbeitet 21.11.2024 06:47:33
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
CVE-2020-19595
- EPSS 0.35%
- Veröffentlicht 05.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:15
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
CVE-2020-19596
- EPSS 0.46%
- Veröffentlicht 05.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:15
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
CVE-2020-21588
- EPSS 0.05%
- Veröffentlicht 02.04.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:12:42
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
CVE-2019-9649
- EPSS 28.94%
- Veröffentlicht 22.03.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:03
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file o...
CVE-2019-9648
- EPSS 19.73%
- Veröffentlicht 22.03.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:02
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned i...
CVE-2018-20658
- EPSS 19.82%
- Veröffentlicht 02.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:56
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
CVE-2018-12113
- EPSS 12.21%
- Veröffentlicht 05.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:37
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
CVE-2014-1215
- EPSS 0.05%
- Veröffentlicht 20.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:03:52
Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data from config.dat and Windows Registry.