Vulnerabilities > Coreftp

DATE CVE VULNERABILITY TITLE RISK
2014-06-25 CVE-2014-4643 Buffer Errors vulnerability in Coreftp Core FTP 2.2
Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.
network
low complexity
coreftp CWE-119
5.0
2014-05-02 CVE-2014-1443 Buffer Errors vulnerability in Coreftp Core FTP 1.2
Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read.
network
low complexity
coreftp CWE-119
4.0
2014-05-02 CVE-2014-1442 Path Traversal vulnerability in Coreftp Core FTP 1.2
Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command.
network
low complexity
coreftp CWE-22
4.0
2014-05-02 CVE-2014-1441 Race Condition vulnerability in Coreftp Core FTP 1.2
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.
network
coreftp CWE-362
4.3
2014-04-04 CVE-2013-3930 Buffer Errors vulnerability in Coreftp Core FTP 1.2/2.1/2.2
Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a CWD command reply.
network
coreftp CWE-119
critical
9.3
2013-03-29 CVE-2013-0130 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Coreftp
Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (application crash) via a long directory name in a (1) DELE, (2) LIST, or (3) VIEW command.
network
high complexity
coreftp CWE-119
5.1
2009-09-30 CVE-2009-3484 Buffer Errors vulnerability in Coreftp Core FTP 2.1
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file.
network
coreftp CWE-119
critical
9.3