Known vulnerabilities in proftpd

Software: proftpd
Software CPE: cpe:2.3:o:fedoraproject:proftpd:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 20
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting proftpd proftpd is affected by 20 known vulnerabilities: 2 high, 14 medium, 4 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU104049 - NULL Pointer Dereference
CVE-2024-57392
CWE-476 Low
No
No
1.3.8c-2.el9, 1.3.8c-3.fc40, 1.3.8c-3.fc41 18.02.2025 SB2025021853
SB2025021855
SB2025021856
and 29 more
#VU84847 - Out-of-bounds read
CVE-2023-51713
CWE-125 Medium
No
No
1.3.6e-6.el8 28.12.2023 SB2023122821
SB2023122823
SB2024032946
and 1 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
1.3.8b-1.el9, 1.3.8b-1.fc38, 1.3.8b-1.fc39 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 344 more
#VU26104 - NULL Pointer Dereference
CVE-2019-19269
CWE-476 Medium
No
No
1.3.3g-13.el6, 1.3.5e-8.el7, 1.3.6b-2.fc30, 1.3.6b-2.fc31 17.03.2020 SB2020022519
SB2020031705
SB2020083115
and 5 more
#VU25595 - Use After Free
CVE-2020-9273
CWE-416 Medium
No
No
1.3.3g-14.el6, 1.3.5e-9.el7, 1.3.6c-1.el8, 1.3.6c-1.fc30, 1.3.6c-1.fc31 25.02.2020 SB2020022519
SB2020022707
SB2020030101
and 8 more
#VU30580 - Improper Certificate Validation
CVE-2019-19271
CWE-295 Medium
No
No
1.3.5e-8.el7 26.11.2019 SB2019112628
SB2020083115
SB2019112925
#VU30581 - NULL Pointer Dereference
CVE-2019-19272
CWE-476 Medium
No
No
1.3.5e-8.el7 26.11.2019 SB2019112628
SB2020083115
SB2019112925
#VU35035 - Improper Certificate Validation
CVE-2019-19270
CWE-295 Medium
No
No
1.3.5e-8.el7, 1.3.6b-2.fc30, 1.3.6b-2.fc31 26.11.2019 SB2016040501
SB2020083115
SB2020011349
and 3 more
#VU22564 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-18217
CWE-835 Medium
No
No
1.3.3g-11.el6, 1.3.5e-6.el7, 1.3.6b-1.fc29, 1.3.6b-1.fc30, 1.3.6b-1.fc31 06.11.2019 SB2019110639
SB2019110640
SB2020021217
and 8 more
#VU20007 - Permissions, Privileges, and Access Controls
CVE-2017-7418
CWE-264 Low
No
No
1.3.5e-1.el7, 1.3.5e-1.fc24, 1.3.5e-1.fc25, 1.3.5e-1.fc26, 1.3.5e-2.el7 08.08.2019 SB2019080821
SB2017042201
SB2019081425
and 7 more
#VU19318 - Improper Access Control
CVE-2019-12815
CWE-284 Medium
No
No
1.3.5e-5.el7, 1.3.6-21.fc29, 1.3.6-21.fc30 23.07.2019 SB2019072303
SB2019080401
SB2019080821
and 7 more
#VU14904 - Improper Access Control
CVE-2015-3306
CWE-284 High
Available
Exploited
1.3.5-5.el7, 1.3.5-5.fc21, 1.3.5-6.fc22 23.09.2018 SB2015051803
SB2015042202
SB2015092644
and 3 more
#VU111812 - Cryptographic Issues
CVE-2009-3639
CWE-310 Medium
No
No
1.3.2b-1.el5 17.08.2017 SB2017081742
SB2009111603
#VU40410 - Security Features
CVE-2016-3125
CWE-254 Medium
No
No
1.3.3g-6.el5, 1.3.3g-10.el6, 1.3.5b-1.el7, 1.3.5b-1.fc22, 1.3.5b-1.fc23, 1.3.5b-1.fc24 05.04.2016 SB2016040501
SB2016031117
SB2016031118
and 4 more
#VU43153 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2012-6095
CWE-362 Low
No
No
1.3.3g-2.el5, 1.3.3g-2.el6, 1.3.3g-6.el5 24.01.2013 SB2013012404
SB2013011812
SB2013011813
and 1 more
#VU32845 - Use After Free
CVE-2011-4130
CWE-416 Medium
No
No
1.3.3g-1.el5, 1.3.3g-1.el6 06.12.2011 SB2011120602
SB2011112109
SB2012021002
and 2 more
#VU111809 - Stack-based buffer overflow
CVE-2010-4221
CWE-121 High
Available
Exploited
1.3.3c-1.el5 15.09.2011 SB2011091501
SB2010110303
#VU111810 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2010-3867
CWE-22 Medium
No
No
1.3.3c-1.el5 15.09.2011 SB2011091502
SB2010110201
SB2010110303
#VU45231 - Improper input validation
CVE-2011-1137
CWE-20 Medium
Available
No
1.3.3e-1.el5, 1.3.3e-1.el6 11.03.2011 SB2011020201
SB2011040501
SB2011040702
and 1 more
#VU45393 - Heap-based Buffer Overflow
CVE-2010-4652
CWE-122 Medium
No
No
1.3.3d-1.el5 02.02.2011 SB2011020201
SB2011011905