Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-6170

26
FAUCET Score

CVE-2006-6170 describes a buffer overflow vulnerability in the tls_x509_name_oneline function within the mod_tls module, primarily affecting ProFTPD 1.3.0a and earlier versions. This flaw allows unauthenticated remote attackers to execute arbitrary code by supplying an excessively large data length argument. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3.0aCPE matchmatch criteria
cpe:2.3:a:proftpd_project:proftpd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
16.98%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1699 is in the 95th percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatvendor investigatingvia nvd_reference
View patch

References

elegerov.blogspot.com / 2006/10/do-you-remember-2-years-old-overflow.html
ExploitVendor Advisory
lists.grok.org.uk / pipermail/full-disclosure/2006-November/050935.html
ExploitVendor Advisory
bugzilla.redhat.com / bugzilla/show_bug.cgi
Vendor Advisory
secunia.com / advisories/23141
Vendor Advisory
secunia.com / advisories/23174
secunia.com / advisories/23179
secunia.com / advisories/23184
secunia.com / advisories/23207
exchange.xforce.ibmcloud.com / vulnerabilities/30554
slackware.com / security/viewer.php
debian.org / security/2006/dsa-1222
gentoo.org / security/en/glsa/glsa-200611-26.xml
mandriva.com / security/advisories
securityfocus.com / archive/1/452228/100/100/threaded
securityfocus.com / archive/1/452872/100/0/threaded
securityfocus.com / archive/1/452993/100/100/threaded
securityfocus.com / bid/21326
trustix.org / errata/2006/0066
vupen.com / english/advisories/2006/4745