Vulnerabilities > Luke Mewburn

DATE CVE VULNERABILITY TITLE RISK
2009-08-21 CVE-2008-7016 Cross-Site Request Forgery (CSRF) vulnerability in Luke Mewburn Tnftpd 20040810/20061217/20080609
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
6.8
2005-01-10 CVE-2004-1294 Unspecified vulnerability in Luke Mewburn Tnftp 20030825
The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
network
low complexity
luke-mewburn
5.0
2004-10-20 CVE-2004-0794 Unspecified vulnerability in Luke Mewburn Lukemftp and Tnftpd
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
network
high complexity
luke-mewburn
5.1
2002-08-12 CVE-2002-0768 Remote Security vulnerability in Linux
Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.
network
low complexity
luke-mewburn suse
7.5
2002-06-18 CVE-2002-0600 Heap Overflow vulnerability in KTH eBones Kerberos4 FTP Client Passive Mode
Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
network
low complexity
kth luke-mewburn
7.5