VendorsTexas Imperial Softwarewftpdall versions
Vulnerabilities

Texas Imperial Software Wftpd

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-1999-0950
Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
Published 2000-04-25 · Modified
10.02 PoCEPSS 0.081
CVE-2001-0694
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.
Published 2001-08-29 · Modified
7.5EPSS 0.016
CVE-2004-0340
Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.
Published 2004-03-18 · Modified
7.21 PoCEPSS 0.013
CVE-2006-4318
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
Published 2006-08-24 · Modified
6.52 PoCEPSS 0.621
CVE-2000-0645
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).
Published 2000-08-03 · Modified
6.41 PoCEPSS 0.049
CVE-2006-5826
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters.
Published 2006-11-10 · Modified
5.81 PoCEPSS 0.108
CVE-2000-0644
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.073
CVE-2000-0647
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.
Published 2000-08-03 · Modified
5.01 PoCEPSS 0.053
CVE-2000-0648
WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.
Published 2000-08-03 · Modified
5.01 PoCEPSS 0.037
CVE-2004-1642
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.
Published 2005-02-20 · Modified
5.01 PoCEPSS 0.031
CVE-2004-2367
The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command.
Published 2005-08-16 · Modified
5.01 PoCEPSS 0.031
CVE-2007-0311
Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.
Published 2007-01-18 · Modified
5.01 PoCEPSS 0.028
CVE-2000-0646
WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.
Published 2000-08-03 · Modified
5.0EPSS 0.022
CVE-2000-1101
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
Published 2002-03-09 · Modified
5.0EPSS 0.019
CVE-2000-0875
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.
Published 2001-05-07 · Modified
5.0EPSS 0.017
CVE-2000-0876
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.
Published 2001-05-07 · Modified
5.0EPSS 0.015
CVE-2001-0695
WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).
Published 2001-08-29 · Modified
5.0EPSS 0.013
CVE-2004-0341
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.
Published 2004-03-18 · Modified
2.1EPSS 0.004