VendorsFileZilla-projectfilezilla_serverall versions
Vulnerabilities

FileZilla-project FileZilla Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Published 2014-04-07 · Analyzed
7.5KEV4 PoCEPSS 1.000
CVE-2014-0224
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Published 2014-06-05 · Modified
7.4EPSS 0.953
CVE-2005-0850
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.
Published 2005-03-24 · Modified
5.0EPSS 0.022
CVE-2005-0851
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.
Published 2005-03-24 · Modified
5.0EPSS 0.022
CVE-2009-0884
Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets.
Published 2009-03-12 · Modified
4.3EPSS 0.034
CVE-2015-10003
FileZilla Server PORT confused deputy
Published 2022-07-17 · Modified
4.3EPSS 0.005
CVE-2006-6565
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.
Published 2006-12-15 · Modified
4.01 PoCEPSS 0.706