Known vulnerabilities in proftpd
Vendor:
Fedoraproject
Software:
proftpd
Software CPE:
cpe:2.3:o:fedoraproject:proftpd:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
20
Public exploits:
4
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.3.9d-2.el10_4
1.3.9d-1.fc44
1.3.9d-1.fc43
1.3.9d-1.el10_2
1.3.9d-1.el10_3
1.3.8d-4.el9
1.3.6e-11.el8
1.3.9c-3.el10_3
1.3.9c-3.el10_2
1.3.9c-3.fc44
1.3.9c-3.fc43
1.3.9c-1.fc44
1.3.9c-1.el10_2
1.3.9c-1.el10_3
1.3.9c-1.fc43
1.3.9b-2.fc45
1.3.8d-3.el9
1.3.6e-10.el8
1.3.9a-2.el10_2
1.3.9a-2.el10_1
1.3.9a-2.el10_3
1.3.9a-2.fc43
1.3.9a-2.fc44
1.3.9a-2.fc45
1.3.9a-1.fc44
1.3.9a-1.el10_3
1.3.9a-1.fc42
1.3.9a-1.fc43
1.3.9a-1.el10_1
1.3.9a-1.el10_2
1.3.8d-2.el9
1.3.3g-15.el6
1.3.5e-10.el7
1.3.3g-14.el6
1.3.5e-9.el7
1.3.6c-1.el8
1.3.6c-1.fc31
1.3.6c-1.fc30
1.3.6b-3.el8
1.3.6b-2.fc31
1.3.6b-2.fc30
1.3.5e-8.el7
1.3.3g-13.el6
1.3.3g-11.el6
1.3.5e-6.el7
1.3.6b-1.fc31
1.3.6b-1.fc30
1.3.6b-1.fc29
1.3.5e-5.el7
1.3.6-21.fc29
1.3.6-21.fc30
1.3.5e-2.el7
1.3.5e-1.el7
1.3.5e-1.fc25
1.3.5e-1.fc26
1.3.5e-1.fc24
1.3.3g-6.el5
1.3.3g-10.el6
1.3.5b-1.fc22
1.3.5b-1.el7
1.3.5b-1.fc23
1.3.5b-1.fc24
1.3.5a-2.el7
1.3.5a-5.fc23
1.3.5a-5.fc22
1.3.5-5.el7
1.3.5-6.fc22
1.3.5-5.fc21
1.3.3g-3.el5
1.3.3g-3.el6
1.3.3g-2.el5
1.3.3g-2.el6
1.3.3g-1.el5
1.3.3g-1.el6
1.3.3e-1.el6
1.3.3e-1.el5
1.3.3d-1.el5
1.3.3c-1.el5
1.3.8c-2.el9
1.3.8c-3.fc41
1.3.8c-3.fc40
1.3.6e-4.el8
1.3.5e-11.el7
1.3.7c-1.fc35
1.3.7c-1.fc33
1.3.7c-1.fc34
1.3.6e-6.el8
1.3.8b-1.el9
1.3.8b-1.fc39
1.3.8b-1.fc38
1.3.2d-1.el5
1.3.2b-1.el5
Vulnerabilities (20)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU104049 - NULL Pointer Dereference CVE-2024-57392 |
CWE-476 | Low | 1.3.8c-2.el9, 1.3.8c-3.fc40, 1.3.8c-3.fc41 | 18.02.2025 |
SB2025021853 SB2025021855 SB2025021856 and 29 more |
||
| #VU84847 - Out-of-bounds read CVE-2023-51713 |
CWE-125 | Medium | 1.3.6e-6.el8 | 28.12.2023 |
SB2023122821 SB2023122823 SB2024032946 and 1 more |
||
| #VU84537 - Inadequate Encryption Strength CVE-2023-48795 |
CWE-326 | Low | 1.3.8b-1.el9, 1.3.8b-1.fc38, 1.3.8b-1.fc39 | 19.12.2023 |
SB2023121903 SB2023121905 SB2023121906 and 344 more |
||
| #VU26104 - NULL Pointer Dereference CVE-2019-19269 |
CWE-476 | Medium | 1.3.3g-13.el6, 1.3.5e-8.el7, 1.3.6b-2.fc30, 1.3.6b-2.fc31 | 17.03.2020 |
SB2020022519 SB2020031705 SB2020083115 and 5 more |
||
| #VU25595 - Use After Free CVE-2020-9273 |
CWE-416 | Medium | 1.3.3g-14.el6, 1.3.5e-9.el7, 1.3.6c-1.el8, 1.3.6c-1.fc30, 1.3.6c-1.fc31 | 25.02.2020 |
SB2020022519 SB2020022707 SB2020030101 and 8 more |
||
| #VU30580 - Improper Certificate Validation CVE-2019-19271 |
CWE-295 | Medium | 1.3.5e-8.el7 | 26.11.2019 |
SB2019112628 SB2020083115 SB2019112925 |
||
| #VU30581 - NULL Pointer Dereference CVE-2019-19272 |
CWE-476 | Medium | 1.3.5e-8.el7 | 26.11.2019 |
SB2019112628 SB2020083115 SB2019112925 |
||
| #VU35035 - Improper Certificate Validation CVE-2019-19270 |
CWE-295 | Medium | 1.3.5e-8.el7, 1.3.6b-2.fc30, 1.3.6b-2.fc31 | 26.11.2019 |
SB2016040501 SB2020083115 SB2020011349 and 3 more |
||
| #VU22564 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2019-18217 |
CWE-835 | Medium | 1.3.3g-11.el6, 1.3.5e-6.el7, 1.3.6b-1.fc29, 1.3.6b-1.fc30, 1.3.6b-1.fc31 | 06.11.2019 |
SB2019110639 SB2019110640 SB2020021217 and 8 more |
||
| #VU20007 - Permissions, Privileges, and Access Controls CVE-2017-7418 |
CWE-264 | Low | 1.3.5e-1.el7, 1.3.5e-1.fc24, 1.3.5e-1.fc25, 1.3.5e-1.fc26, 1.3.5e-2.el7 | 08.08.2019 |
SB2019080821 SB2017042201 SB2019081425 and 7 more |
||
| #VU19318 - Improper Access Control CVE-2019-12815 |
CWE-284 | Medium | 1.3.5e-5.el7, 1.3.6-21.fc29, 1.3.6-21.fc30 | 23.07.2019 |
SB2019072303 SB2019080401 SB2019080821 and 7 more |
||
| #VU14904 - Improper Access Control CVE-2015-3306 |
CWE-284 | High | 1.3.5-5.el7, 1.3.5-5.fc21, 1.3.5-6.fc22 | 23.09.2018 |
SB2015051803 SB2015042202 SB2015092644 and 3 more |
||
| #VU111812 - Cryptographic Issues CVE-2009-3639 |
CWE-310 | Medium | 1.3.2b-1.el5 | 17.08.2017 |
SB2017081742 SB2009111603 |
||
| #VU40410 - Security Features CVE-2016-3125 |
CWE-254 | Medium | 1.3.3g-6.el5, 1.3.3g-10.el6, 1.3.5b-1.el7, 1.3.5b-1.fc22, 1.3.5b-1.fc23, 1.3.5b-1.fc24 | 05.04.2016 |
SB2016040501 SB2016031117 SB2016031118 and 4 more |
||
| #VU43153 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2012-6095 |
CWE-362 | Low | 1.3.3g-2.el5, 1.3.3g-2.el6, 1.3.3g-6.el5 | 24.01.2013 |
SB2013012404 SB2013011812 SB2013011813 and 1 more |
||
| #VU32845 - Use After Free CVE-2011-4130 |
CWE-416 | Medium | 1.3.3g-1.el5, 1.3.3g-1.el6 | 06.12.2011 |
SB2011120602 SB2011112109 SB2012021002 and 2 more |
||
| #VU111809 - Stack-based buffer overflow CVE-2010-4221 |
CWE-121 | High | 1.3.3c-1.el5 | 15.09.2011 |
SB2011091501 SB2010110303 |
||
| #VU111810 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2010-3867 |
CWE-22 | Medium | 1.3.3c-1.el5 | 15.09.2011 |
SB2011091502 SB2010110201 SB2010110303 |
||
| #VU45231 - Improper input validation CVE-2011-1137 |
CWE-20 | Medium | 1.3.3e-1.el5, 1.3.3e-1.el6 | 11.03.2011 |
SB2011020201 SB2011040501 SB2011040702 and 1 more |
||
| #VU45393 - Heap-based Buffer Overflow CVE-2010-4652 |
CWE-122 | Medium | 1.3.3d-1.el5 | 02.02.2011 |
SB2011020201 SB2011011905 |