VendorsSteve Poulsenguildftpdall versions
Vulnerabilities

Steve Poulsen Guildftpd

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2000-0640
Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.
Published 2000-10-13 · Modified
7.51 PoCEPSS 0.072
CVE-2001-0770
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.
Published 2002-06-25 · Modified
7.5EPSS 0.032
CVE-2006-5133
Buffer overflow in GuildFTPd 0.999.13 allows remote attackers to have an unknown impact, possibly code execution related to input containing "globbing chars."
Published 2006-10-02 · Modified
7.5EPSS 0.031
CVE-2001-0767
Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.
Published 2001-10-12 · Modified
5.0EPSS 0.017
CVE-2003-1267
GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.
Published 2005-11-16 · Modified
5.0EPSS 0.017
CVE-2001-0769
Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character.
Published 2002-06-25 · Modified
5.0EPSS 0.013
CVE-2001-0768
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
Published 2001-10-12 · Modified
4.6EPSS 0.003