Lucene search

K

Ftp Client Security Vulnerabilities

cve
cve

CVE-2023-37881

Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <=...

8.8CVSS

8.7AI Score

0.001EPSS

2023-09-12 09:15 AM
18
cve
cve

CVE-2023-37879

Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <=...

7.5CVSS

7.4AI Score

0.001EPSS

2023-09-12 09:15 AM
22
cve
cve

CVE-2023-37878

Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <=...

8.8CVSS

8.7AI Score

0.001EPSS

2023-09-12 09:15 AM
13
cve
cve

CVE-2023-37875

Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <=...

5.4CVSS

5.4AI Score

0.0004EPSS

2023-09-12 09:15 AM
18
cve
cve

CVE-2022-27665

Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add...

6.1CVSS

7.2AI Score

0.001EPSS

2023-04-03 02:15 PM
23
cve
cve

CVE-2023-22551

The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a denial of service (memory consumption) by engaging in client activity, such as establishing and then terminating a connection. This occurs because malloc is used but free is.....

7.5CVSS

7.4AI Score

0.002EPSS

2023-01-01 06:15 PM
27
cve
cve

CVE-2002-1851

Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack...

7.8AI Score

0.007EPSS

2022-10-03 04:23 PM
17
cve
cve

CVE-2010-3102

Directory traversal vulnerability in SiteDesigner Technologies, Inc. 3D-FTP Client 9.0 build 2, and probably earlier versions, allows remote FTP servers to write arbitrary files via a ".." (dot dot backslash) in a...

6.9AI Score

0.002EPSS

2022-10-03 04:20 PM
26
cve
cve

CVE-2010-3100

Directory traversal vulnerability in Porta+ FTP Client 4.1, and possibly other versions, allows remote FTP servers to overwrite arbitrary files via a directory traversal sequences in a...

7AI Score

0.002EPSS

2022-10-03 04:20 PM
19
cve
cve

CVE-2014-4643

Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP...

8.1AI Score

0.009EPSS

2022-10-03 04:20 PM
27
cve
cve

CVE-2019-9600

The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain...

7.5CVSS

7.3AI Score

0.006EPSS

2022-10-03 04:19 PM
23
cve
cve

CVE-2019-25046

The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG...

6.1CVSS

5.9AI Score

0.001EPSS

2021-06-10 12:15 PM
56
6
cve
cve

CVE-2016-5764

Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connects to a malicious...

8.8CVSS

9AI Score

0.013EPSS

2016-10-27 08:59 PM
28
cve
cve

CVE-2014-0605

Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings...

7.9AI Score

0.495EPSS

2015-02-06 11:59 AM
16
cve
cve

CVE-2014-0604

Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog...

7.9AI Score

0.495EPSS

2015-02-06 11:59 AM
14
cve
cve

CVE-2014-0603

The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference...

7.8AI Score

0.721EPSS

2015-02-06 11:59 AM
46
cve
cve

CVE-2014-5211

Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD...

8.2AI Score

0.036EPSS

2015-01-27 08:59 PM
14
cve
cve

CVE-2010-4095

Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via a .. (dot dot) in a filename in a server...

6.9AI Score

0.004EPSS

2010-10-26 08:00 PM
18
cve
cve

CVE-2010-3096

Directory traversal vulnerability in SoftX FTP Client 3.3 and possibly earlier allows remote FTP servers to write arbitrary files via ".." (dot dot backslash) sequences in a...

7.1AI Score

0.003EPSS

2010-08-20 08:00 PM
29
cve
cve

CVE-2010-1465

Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV...

8.2AI Score

0.495EPSS

2010-04-16 07:30 PM
29
cve
cve

CVE-2008-5754

Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to...

8AI Score

0.07EPSS

2008-12-30 05:30 PM
20
cve
cve

CVE-2008-5753

Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry with a long host name, which appears as a host parameter within the quick-connect...

7.6AI Score

0.009EPSS

2008-12-30 05:30 PM
25
cve
cve

CVE-2008-5045

Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to cause a denial of service (crash) via a 200 server response that is exactly 1024 characters...

7.2AI Score

0.006EPSS

2008-11-13 01:00 AM
26
cve
cve

CVE-2008-3795

Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message...

7AI Score

0.005EPSS

2008-08-27 03:21 PM
29
cve
cve

CVE-2008-2889

Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to...

6.5AI Score

0.003EPSS

2008-06-27 06:41 PM
26
cve
cve

CVE-2008-2894

Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to...

6.5AI Score

0.002EPSS

2008-06-27 06:41 PM
19
cve
cve

CVE-2008-2822

Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a (1) LIST or (2) MLSD...

6.9AI Score

0.002EPSS

2008-06-23 05:41 PM
17
cve
cve

CVE-2008-2821

Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to...

6.4AI Score

0.001EPSS

2008-06-23 05:41 PM
19
cve
cve

CVE-2008-2519

Directory traversal vulnerability in Core FTP client 2.1 Build 1565 allows remote FTP servers to create or overwrite arbitrary files via .. (dot dot) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup...

7.2AI Score

0.002EPSS

2008-06-03 02:32 PM
29
cve
cve

CVE-2003-1472

Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long...

8.3AI Score

0.008EPSS

2007-10-24 11:00 PM
26
cve
cve

CVE-2003-1368

Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server...

8AI Score

0.144EPSS

2007-10-17 01:00 AM
19
cve
cve

CVE-2007-3161

Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long...

7.8AI Score

0.007EPSS

2007-06-11 10:30 PM
20
cve
cve

CVE-2004-2037

Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP...

8.1AI Score

0.177EPSS

2005-05-10 04:00 AM
31
cve
cve

CVE-2004-1280

The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a...

8AI Score

0.004EPSS

2005-01-10 05:00 AM
22
cve
cve

CVE-2004-1281

The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a...

7.1AI Score

0.001EPSS

2005-01-10 05:00 AM
18
cve
cve

CVE-2004-1327

Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long...

8.3AI Score

0.008EPSS

2005-01-06 05:00 AM
21
cve
cve

CVE-2004-0739

Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long...

8.3AI Score

0.005EPSS

2004-07-27 04:00 AM
26
cve
cve

CVE-2003-0766

Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER command, or (3) a long response to a PASS...

8.2AI Score

0.004EPSS

2003-09-17 04:00 AM
24
cve
cve

CVE-2003-0371

Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP...

8.3AI Score

0.004EPSS

2003-06-16 04:00 AM
20
cve
cve

CVE-2003-0041

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the...

7.4AI Score

0.008EPSS

2003-02-19 05:00 AM
30
cve
cve

CVE-2002-0608

Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220"...

8.2AI Score

0.011EPSS

2002-06-18 04:00 AM
22
cve
cve

CVE-1999-1562

gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log...

6.7AI Score

0.001EPSS

2001-09-12 04:00 AM
24
cve
cve

CVE-1999-0351

FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a...

6.5AI Score

0.009EPSS

1999-09-29 04:00 AM
102
1