VendorsMaxum Development Corporationrumpus_ftp_serverall versions
Vulnerabilities

Maxum Development Corporation Rumpus FTP Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2001-0644
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server.
Published 2002-03-09 · Modified
7.5EPSS 0.015
CVE-2007-0019
Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.
Published 2007-01-19 · Modified
6.51 PoCEPSS 0.038
CVE-2001-0646
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.
Published 2002-03-09 · Modified
5.01 PoCEPSS 0.032
CVE-2007-0366
Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.
Published 2007-01-19 · Modified
4.6EPSS 0.004
CVE-2007-0367
Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.
Published 2007-01-19 · Modified
4.6EPSS 0.004
CVE-2001-0706
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.
Published 2002-03-09 · Modified
2.11 PoCEPSS 0.010