Filezilla-Project Filezilla Server vulnerabilities

7 known vulnerabilities affecting filezilla-project/filezilla_server.

Total CVEs
7
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2015-10003MEDIUMCVSS 4.3fixed in 0.9.512022-07-17
CVE-2015-10003 [MEDIUM] CWE-441 CVE-2015-10003: A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. Th A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It is recommended to upgrade the af
nvd
CVE-2014-0224HIGHCVSS 7.4fixed in 0.9.452014-06-05
CVE-2014-0224 [HIGH] CWE-326 CVE-2014-0224: OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict proc OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS hand
nvd
CVE-2014-0160HIGHCVSS 7.5KEVPoCfixed in 0.9.442014-04-07
CVE-2014-0160 [HIGH] CWE-125 CVE-2014-0160: The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heart The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed b
nvd
CVE-2009-0884MEDIUMCVSS 4.3PoCfixed in 0.9.312009-03-12
CVE-2009-0884 [MEDIUM] CWE-120 CVE-2009-0884: Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of servi Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets.
nvd
CVE-2006-6565MEDIUMCVSS 4.0PoCfixed in 0.9.222006-12-15
CVE-2006-6565 [MEDIUM] CVE-2006-6565: FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wi FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.
nvd
CVE-2005-0850MEDIUMCVSS 5.0PoCfixed in 0.9.62005-05-02
CVE-2005-0850 [MEDIUM] CWE-20 CVE-2005-0850: FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.
nvd
CVE-2005-0851MEDIUMCVSS 5.0PoCfixed in 0.9.62005-05-02
CVE-2005-0851 [MEDIUM] CWE-835 CVE-2005-0851: FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.
nvd