Vendorshfiref0xlightftpall versions
Vulnerabilities

hfiref0x Lightftp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-1000218
LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.
Published 2017-11-17 · Modified
9.8EPSS 0.034
CVE-2023-24042
A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.
Published 2023-01-21 · Modified
7.5EPSS 0.005
CVE-2025-65403
A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-12-01 · Analyzed
6.5EPSS 0.003