CVE-2024-48208
- EPSS 3.19%
- Published 24.10.2024 21:15:14
- Last modified 04.09.2025 16:33:12
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
CVE-2021-40524
- EPSS 0.57%
- Published 05.09.2021 19:15:15
- Last modified 21.11.2024 06:24:19
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does no...
CVE-2020-35359
- EPSS 0.46%
- Published 26.12.2020 05:15:11
- Last modified 21.11.2024 05:27:13
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
CVE-2020-9274
- EPSS 1.27%
- Published 26.02.2020 16:15:19
- Last modified 21.11.2024 05:40:19
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the...
CVE-2020-9365
- EPSS 1.53%
- Published 24.02.2020 16:15:13
- Last modified 21.11.2024 05:40:29
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
CVE-2019-20176
- EPSS 0.45%
- Published 31.12.2019 15:15:11
- Last modified 21.11.2024 04:38:09
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CVE-2017-12170
- EPSS 0.33%
- Published 21.09.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications be...
CVE-2011-3171
- EPSS 0.02%
- Published 04.11.2011 21:55:02
- Last modified 11.04.2025 00:51:21
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwri...
- EPSS 14.63%
- Published 24.05.2011 23:55:01
- Last modified 11.04.2025 00:51:21
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP...
CVE-2011-1575
- EPSS 22.18%
- Published 23.05.2011 22:55:01
- Last modified 11.04.2025 00:51:21
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed ...