VendorsNetBSDtnftpdall versions
Vulnerabilities

NetBSD Tnftpd

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-45198
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
Published 2023-10-05 · Modified
7.5EPSS 0.005
CVE-2015-5917
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.
Published 2015-10-09 · Modified
5.0EPSS 0.027