Atftp Project maintains a lightweight TFTP server implementation, a narrowly scoped utility for simple file transfer in embedded and legacy network environments. The product's observed vulnerability profile centers on memory-safety issues including buffer overflows, out-of-bounds reads and writes, NULL-pointer dereferences, and reachable assertions, which are characteristic of C-based network daemons handling untrusted input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atftp Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11365CRITICAL An issue was discovered in atftpd in atftp 0.7.1. A remote attacker may send a crafted packet triggering a stack-based buffer overflow due to an insecurely implemented strncpy call | Apr 20, 2019 | 9.8 | 32 | NO | NO |
CVE-2021-41054HIGH tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options. | Sep 13, 2021 | 7.5 | 26 | NO | NO |
CVE-2019-11366MEDIUM An issue was discovered in atftpd in atftp 0.7.1. It does not lock the thread_list_mutex mutex before assigning the current thread data structure. As a result, the daemon is vulner | Apr 20, 2019 | 5.9 | 22 | NO | NO |
CVE-2020-6097HIGH An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests tri | Sep 10, 2020 | 7.5 | 20 | NO | NO |
CVE-2021-46671MEDIUM options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client. | Feb 4, 2022 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atftp Project.
Media articles that mention a CVE ID that affects a product developed by Atftp Project — matched by CVE ID, not by vendor name.