Bftpd is a lightweight FTP server implementation with a narrow product scope but notable deployment in embedded and resource-constrained environments. The durable vulnerability signal centers on memory-safety issues, particularly improper buffer-boundary handling, which is characteristic of native C implementations in network services. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bftpd over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-6162CRITICAL An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups | Jan 10, 2020 | 9.1 | 29 | NO | NO |
CVE-2020-6835CRITICAL An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking. | Jan 10, 2020 | 9.8 | 24 | NO | NO |
CVE-2007-2010MEDIUM Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command. | Apr 12, 2007 | 6.8 | 24 | NO | NO |
CVE-2017-16892HIGH In Bftpd before 4.7, there is a memory leak in the file rename function. | Nov 19, 2017 | 7.5 | 19 | NO | NO |
CVE-2007-2051MEDIUM Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable. | Apr 16, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bftpd.
Media articles that mention a CVE ID that affects a product developed by Bftpd — matched by CVE ID, not by vendor name.