Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freefloat

First CVE: Jun 20, 2014Active for: 12 yearsTotal CVEs: 51
57.8
VTI Score
TOP TARGET

Freefloat develops legacy FTP server software that, despite a very narrow product scope, occupies a well-represented position in the vulnerability landscape, likely reflecting long service lifespans and continued deployment in maintenance-critical environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making patches from this vendor priority material for defenders managing exposed or legacy FTP infrastructure. The exposure recurs consistently across its FTP server products through a durable set of memory-safety and access-control weakness classes: buffer overflows and out-of-bounds writes characteristic of native C implementations, alongside missing authentication controls and improper permission assignments that compound the risk of internet-reachable instances. Defenders should treat Freefloat advisories as high-risk and prioritize inventory and isolation of affected FTP services; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
51
Total CVEs
More Total CVEs than 98% of tracked vendors
8.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
9.8
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freefloat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2014
12 years ago
Most Recent CVE
Mar 22, 2026
124 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-5106HIGH
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.
Jun 20, 201410.049NOYES
CVE-2012-10030CRITICAL
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accep
Aug 5, 20259.842NOYES
CVE-2012-10023CRITICAL
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote at
Aug 5, 20259.842NOYES
CVE-2025-5548CRITICAL
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Command Handler. The manipulation le
Jun 4, 20259.841NOYES
CVE-2019-25614CRITICAL
Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request wit
Mar 22, 20269.832NONO
CVE-2025-5219CRITICAL
A vulnerability has been found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ASCII Command H
May 27, 20259.830NONO
CVE-2025-5218CRITICAL
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.0. Affected is an unknown function of the component LITERAL Command Handler. The manipulati
May 27, 20259.830NONO
CVE-2025-5076CRITICAL
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND Command Handler. The ma
May 22, 20259.830NONO
CVE-2025-5050CRITICAL
A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown processing of the component BELL Command Handler. The manipula
May 21, 20259.830NONO
CVE-2025-5549CRITICAL
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component PASV Command Hand
Jun 4, 20259.829NONO
View all 51 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products51 CVEs
98%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network50 (98.0%)
Unknown1 (2.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (98.0%)
High0 (0.0%)
Unknown1 (2.0%)
User Interaction
None50 (98.0%)
Unknown1 (2.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None50 (98.0%)
Unknown1 (2.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.9% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
3.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freefloat.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freefloat — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freefloat's Products

View all 3 CNAs →

Top CWEs