Acftp is a focused file-transfer application with a narrow vulnerability footprint centered on improper authentication controls, a fundamental concern for software handling credential-based access. Current severity, exploitation activity, and exposure metrics are shown in the live statistics panel alongside this summary.
The number and severity of CVEs published that impact products developed by Acftp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2417HIGH acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity fr | Dec 31, 2002 | 10.0 | 43 | NO | YES |
CVE-2006-2242MEDIUM acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command. | May 9, 2006 | 5.0 | 23 | NO | YES |
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command. | Dec 27, 2006 | 3.5 | 20 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acftp.
Media articles that mention a CVE ID that affects a product developed by Acftp — matched by CVE ID, not by vendor name.