Vulnerabilities > Netwin > Surgeftp > 2.3a2

DATE CVE VULNERABILITY TITLE RISK
2013-08-09 CVE-2013-4742 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Netwin Surgeftp
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
network
low complexity
netwin CWE-119
7.5
2008-02-27 CVE-2008-1052 Buffer Errors vulnerability in Netwin Surgeftp 2.3A2
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.
network
low complexity
netwin CWE-119
6.4