Washington University Wu-Ftpd vulnerabilities
17 known vulnerabilities affecting washington_university/wu-ftpd.
Total CVEs
17
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH6MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2005-0256MEDIUMCVSS 5.0PoCv2.6.1v2.6.22005-05-02
CVE-2005-0256 [MEDIUM] CWE-119 CVE-2005-0256: The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause
The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.
nvd
CVE-2004-0148HIGHCVSS 7.2v2.4.1v2.4.2_beta2+19 more2004-04-15
CVE-2004-0148 [HIGH] CVE-2004-0148: wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass acce
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
nvd
CVE-2004-0185CRITICALCVSS 10.0v2.6.22004-03-15
CVE-2004-0185 [CRITICAL] CVE-2004-0185: Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows re
Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.
nvd
CVE-2003-1327CRITICALCVSS 9.3≤ 2.6.22003-12-31
CVE-2003-1327 [CRITICAL] CVE-2003-1327: Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADM
Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administr
nvd
CVE-2003-1329HIGHCVSS 7.8v2.6.22003-12-31
CVE-2003-1329 [HIGH] CVE-2003-1329: ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket
ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.
nvd
CVE-2003-0853MEDIUMCVSS 5.0PoCv2.4.1v2.4.2_beta2+19 more2003-11-17
CVE-2003-0853 [MEDIUM] CVE-2003-0853: An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a de
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.
nvd
CVE-2003-0854LOWCVSS 2.1PoCv2.4.1v2.4.2_beta2+19 more2003-11-17
CVE-2003-0854 [LOW] CVE-2003-0854: ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.
nvd
CVE-2001-0550HIGHCVSS 7.5PoCv2.5.0v2.6.0+1 more2001-11-30
CVE-2001-0550 [HIGH] CVE-2001-0550: wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
nvd
CVE-2001-0935HIGHCVSS 7.5v2.4v2.6.0+1 more2001-11-28
CVE-2001-0935 [HIGH] CVE-2001-0935: Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug
Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.
nvd
CVE-2001-0187CRITICALCVSS 10.0PoCv2.4.1v2.4.2_beta9+17 more2001-03-26
CVE-2001-0187 [CRITICAL] CVE-2001-0187: Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allow
Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.
nvd
CVE-2000-0574MEDIUMCVSS 5.0PoCv2.4.2_beta1v2.4.2_beta18+16 more2000-07-07
CVE-2000-0574 [MEDIUM] CVE-2000-0574: FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untruste
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
nvd
CVE-1999-0878CRITICALCVSS 10.0v2.4.2_beta18_vr4v2.4.2_beta18_vr5+12 more1999-08-22
CVE-1999-0878 [CRITICAL] CVE-1999-0878: Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges v
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.
nvd
CVE-1999-0368CRITICALCVSS 10.0PoCv2.4.2_beta18v2.4.2_beta18_vr91999-02-09
CVE-1999-0368 [CRITICAL] CVE-1999-0368: Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
nvd
CVE-1999-0017HIGHCVSS 7.5v2.41997-12-10
CVE-1999-0017 [HIGH] CVE-1999-0017: FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP clien
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
nvd
CVE-1999-0955HIGHCVSS 7.6v2.4.11997-09-23
CVE-1999-0955 [HIGH] CVE-1999-0955: Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXE
Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command.
nvd
CVE-1999-1326MEDIUMCVSS 5.0v2.41997-07-04
CVE-1999-1326 [MEDIUM] CVE-1999-1326: wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command
wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
nvd
CVE-1999-0080CRITICALCVSS 10.0v2.41995-11-30
CVE-1999-0080 [CRITICAL] CVE-1999-0080: Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dan
Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.
nvd