Vulnerabilities > Smartftp

DATE CVE VULNERABILITY TITLE RISK
2012-09-06 CVE-2010-5219 Unspecified vulnerability in Smartftp .0.1140.0
Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .txt, .html, or .mpg file.
local
smartftp
6.9
2011-10-07 CVE-2010-4871 Unspecified vulnerability in Smartftp 2.0
Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.
network
low complexity
smartftp
critical
10.0
2010-08-20 CVE-2010-3099 Path Traversal vulnerability in Smartftp
Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.
network
smartftp CWE-22
critical
9.3
2007-02-06 CVE-2007-0790 Buffer Errors vulnerability in Smartftp 2.0.1002
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
network
low complexity
smartftp CWE-119
7.5
2003-12-31 CVE-2003-1319 Buffer Overflow vulnerability in SmartFTP PWD Command Request
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
network
high complexity
smartftp
7.6