ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-48208
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow.

pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

NVD description · AI analysis pending
8.62% PoC
  • pureftpd pure-ftpd
CVE-2021-40524
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial

In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)

NVD description · AI analysis pending
7.54% PoC
  • pureftpd pure-ftpd
CVE-2020-35359
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

NVD description · AI analysis pending
7.55% PoC
  • pureftpd pure-ftpd
CVE-2020-9274
An issue was discovered in Pure-FTPd 1.0.49.

An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.

NVD description · AI analysis pending
7.56%
  • pureftpd pure-ftpd
  • pureftpd debian linux
  • pureftpd extra packages for enterprise linux
  • +1 more
CVE-2020-9365
An issue was discovered in Pure-FTPd 1.0.49.

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

NVD description · AI analysis pending
7.57%
  • pureftpd pure-ftpd
  • pureftpd fedora
CVE-2019-20176
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.

In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.

NVD description · AI analysis pending
7.54%
  • pureftpd pure-ftpd
  • pureftpd fedora
CVE-2017-12170
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update

Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.

NVD description · AI analysis pending
9.82%
  • pureftpd pure-ftpd
  • pureftpd fedora