Freefloat develops legacy FTP server software that, despite a very narrow product scope, occupies a well-represented position in the vulnerability landscape, likely reflecting long service lifespans and continued deployment in maintenance-critical environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making patches from this vendor priority material for defenders managing exposed or legacy FTP infrastructure. The exposure recurs consistently across its FTP server products through a durable set of memory-safety and access-control weakness classes: buffer overflows and out-of-bounds writes characteristic of native C implementations, alongside missing authentication controls and improper permission assignments that compound the risk of internet-reachable instances. Defenders should treat Freefloat advisories as high-risk and prioritize inventory and isolation of affected FTP services; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freefloat over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5106HIGH Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command. | Jun 20, 2014 | 10.0 | 49 | NO | YES |
CVE-2012-10030CRITICAL FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accep | Aug 5, 2025 | 9.8 | 42 | NO | YES |
CVE-2012-10023CRITICAL A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote at | Aug 5, 2025 | 9.8 | 42 | NO | YES |
CVE-2025-5548CRITICAL A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Command Handler. The manipulation le | Jun 4, 2025 | 9.8 | 41 | NO | YES |
CVE-2019-25614CRITICAL Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request wit | Mar 22, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-5219CRITICAL A vulnerability has been found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ASCII Command H | May 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-5218CRITICAL A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.0. Affected is an unknown function of the component LITERAL Command Handler. The manipulati | May 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-5076CRITICAL A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND Command Handler. The ma | May 22, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-5050CRITICAL A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown processing of the component BELL Command Handler. The manipula | May 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-5549CRITICAL A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component PASV Command Hand | Jun 4, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freefloat.
Media articles that mention a CVE ID that affects a product developed by Freefloat — matched by CVE ID, not by vendor name.