Proftpd

Proftpd · 53 CVEs

CVE-2026-63091
HIGH

ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser

Jul 20, 2026

CVE-2026-63090
HIGH

ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly

Jul 20, 2026

CVE-2026-53994
HIGH

ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation

Jul 18, 2026

CVE-2026-35025
HIGH

ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR

Jun 24, 2026

CVE-2026-44331
HIGH

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wra…

May 5, 2026

CVE-2026-42167
HIGH

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where t…

Apr 28, 2026

CVE-2021-47865
HIGH

ProFTPD 1.3.7a - Remote Denial of Service

Jan 21, 2026

CVE-2010-20103
CRITICAL

ProFTPD 1.3.3c Backdoor Command Execution

Aug 20, 2025

CVE-2024-48651
HIGH

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of t…

Nov 29, 2024

CVE-2023-51713
HIGH

make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishand…

Dec 22, 2023

CVE-2023-48795
MEDIUM

ssh: Prefix truncation attack on Binary Packet Protocol (BPP)

Dec 18, 2023

CVE-2021-46854
HIGH

mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 character…

Nov 23, 2022

CVE-2020-9273
HIGH

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a…

Feb 20, 2020

CVE-2020-9272
HIGH

ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.

Feb 20, 2020

CVE-2019-19269
MEDIUM

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This po…

Nov 26, 2019

CVE-2019-19270
HIGH

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CR…

Nov 26, 2019

CVE-2019-19271
HIGH

An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a cli…

Nov 26, 2019

CVE-2019-19272
HIGH

An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable ini…

Nov 26, 2019

CVE-2019-18217
HIGH

ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect hand…

Oct 21, 2019

CVE-2019-12815
CRITICAL

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and informati…

Jul 19, 2019

CVE-2017-7418
MEDIUM

ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic…

Apr 4, 2017

CVE-2016-3125
HIGH

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile direc…

Apr 5, 2016

CVE-2015-3306
HIGH

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and…

May 18, 2015

CVE-2013-4359
MEDIUM

Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of ser…

Sep 30, 2013

CVE-2012-6095
LOW

ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary fi…

Jan 24, 2013

Showing 1 to 25 of 53 CVEs