Vulnerabilities > Psftp

DATE CVE VULNERABILITY TITLE RISK
2017-11-15 CVE-2017-15272 Insufficiently Protected Credentials vulnerability in Psftp Psftpd 10.0.4
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat.
local
low complexity
psftp CWE-522
5.3
2017-11-15 CVE-2017-15271 Use After Free vulnerability in Psftp Psftpd 10.0.4
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729.
network
high complexity
psftp CWE-416
5.9
2017-11-15 CVE-2017-15270 Improper Input Validation vulnerability in Psftp Psftpd 10.0.4
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file.
network
low complexity
psftp CWE-20
5.3
2017-11-15 CVE-2017-15269 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Psftp Psftpd 10.0.4
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default.
network
low complexity
psftp CWE-610
4.3