Vulnerabilities > Proftpd > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-48795 Improper Validation of Integrity Check Value vulnerability in multiple products
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.
5.9
2020-02-20 CVE-2020-9272 Out-of-bounds Read vulnerability in multiple products
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
network
low complexity
proftpd siemens opensuse CWE-125
5.0
2019-11-30 CVE-2019-19269 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.
network
low complexity
proftpd fedoraproject debian CWE-476
4.9
2019-11-26 CVE-2019-19272 NULL Pointer Dereference vulnerability in Proftpd
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
network
low complexity
proftpd CWE-476
5.0
2019-11-26 CVE-2019-19271 Improper Certificate Validation vulnerability in Proftpd
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.
network
low complexity
proftpd CWE-295
5.0
2016-04-05 CVE-2016-3125 Cryptographic Issues vulnerability in multiple products
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.
network
low complexity
proftpd opensuse fedoraproject CWE-310
5.0
2013-09-30 CVE-2013-4359 Numeric Errors vulnerability in Proftpd 1.3.4/1.3.5
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
network
low complexity
proftpd CWE-189
5.0
2011-03-11 CVE-2011-1137 Numeric Errors vulnerability in Proftpd
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.
network
low complexity
proftpd CWE-189
5.0
2011-02-02 CVE-2010-4652 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Proftpd
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
network
proftpd CWE-119
6.8
2010-11-09 CVE-2008-7265 Resource Management Errors vulnerability in Proftpd
The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.
network
low complexity
proftpd CWE-399
4.0