Vulnerabilities (CVE)

Filtered by vendor Coreftp Subscribe
Filtered by product Core Ftp
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22899 1 Coreftp 1 Core Ftp 2023-08-08 2.6 LOW 5.5 MEDIUM
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
CVE-2022-22836 1 Coreftp 1 Core Ftp 2022-01-19 4.0 MEDIUM 6.5 MEDIUM
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
CVE-2020-21588 1 Coreftp 1 Core Ftp 2021-04-08 2.1 LOW 5.5 MEDIUM
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
CVE-2019-9648 1 Coreftp 1 Core Ftp 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
CVE-2019-9649 1 Coreftp 1 Core Ftp 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.