Proftpd
Proftpd · 53 CVEs
ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser
Jul 20, 2026
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
Jul 20, 2026
ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation
Jul 18, 2026
ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
Jun 24, 2026
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wra…
May 5, 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where t…
Apr 28, 2026
ProFTPD 1.3.7a - Remote Denial of Service
Jan 21, 2026
ProFTPD 1.3.3c Backdoor Command Execution
Aug 20, 2025
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of t…
Nov 29, 2024
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishand…
Dec 22, 2023
ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
Dec 18, 2023
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 character…
Nov 23, 2022
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a…
Feb 20, 2020
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
Feb 20, 2020
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This po…
Nov 26, 2019
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CR…
Nov 26, 2019
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a cli…
Nov 26, 2019
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable ini…
Nov 26, 2019
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect hand…
Oct 21, 2019
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and informati…
Jul 19, 2019
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic…
Apr 4, 2017
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile direc…
Apr 5, 2016
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and…
May 18, 2015
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of ser…
Sep 30, 2013
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary fi…
Jan 24, 2013
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-63091 | ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser | HIGH | 0.53% | Jul 20, 2026 |
| CVE-2026-63090 | ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly | HIGH | 0.93% | Jul 20, 2026 |
| CVE-2026-53994 | ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation | HIGH | 0.75% | Jul 18, 2026 |
| CVE-2026-35025 | ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR | HIGH | 0.51% | Jun 24, 2026 |
| CVE-2026-44331 | In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inj… | HIGH | 0.50% | May 5, 2026 |
| CVE-2026-42167 | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an… | HIGH | 7.31% | Apr 28, 2026 |
| CVE-2021-47865 | ProFTPD 1.3.7a - Remote Denial of Service | HIGH | 0.61% | Jan 21, 2026 |
| CVE-2010-20103 | ProFTPD 1.3.3c Backdoor Command Execution | CRITICAL | 5.09% | Aug 20, 2025 |
| CVE-2024-48651 | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_… | HIGH | 2.16% | Nov 29, 2024 |
| CVE-2023-51713 | make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics. | HIGH | 4.25% | Dec 22, 2023 |
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 93.55% | Dec 18, 2023 |
| CVE-2021-46854 | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters. | HIGH | 1.23% | Nov 23, 2022 |
| CVE-2020-9273 | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c,… | HIGH | 12.14% | Feb 20, 2020 |
| CVE-2020-9272 | ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function. | HIGH | 2.11% | Feb 20, 2020 |
| CVE-2019-19269 | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509… | MEDIUM | 1.65% | Nov 26, 2019 |
| CVE-2019-19270 | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rat… | HIGH | 1.14% | Nov 26, 2019 |
| CVE-2019-19271 | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (ins… | HIGH | 1.26% | Nov 26, 2019 |
| CVE-2019-19272 | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when… | HIGH | 0.95% | Nov 26, 2019 |
| CVE-2019-18217 | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because mai… | HIGH | 20.25% | Oct 21, 2019 |
| CVE-2019-12815 | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a… | CRITICAL | 57.61% | Jul 19, 2019 |
| CVE-2017-7418 | ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks con… | MEDIUM | 0.44% | Apr 4, 2017 |
| CVE-2016-3125 | The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than in… | HIGH | 6.98% | Apr 5, 2016 |
| CVE-2015-3306 | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | HIGH | 96.75% | May 18, 2015 |
| CVE-2013-4359 | Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large re… | MEDIUM | 2.99% | Sep 30, 2013 |
| CVE-2012-6095 | ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink a… | LOW | 0.69% | Jan 24, 2013 |
Showing 1 to 25 of 53 CVEs