Freeftpd is a lightweight FTP server deployed in embedded systems and legacy network environments, with its vulnerability profile centered on a single product line. Its disclosures skew toward serious outcomes and have a strong tendency toward public exploit availability, driven by recurring memory-safety weaknesses—classic and stack-based buffer overflows, improper bounds checking, and authentication flaws—that are characteristic of C-based network daemons. Defenders should treat patches for this server as urgent, particularly in air-gapped or legacy network tiers where FTP remains embedded; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeftpd over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3683HIGH Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary | Nov 19, 2005 | 7.5 | 76 | NO | YES |
CVE-2006-2407HIGH Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, all | May 16, 2006 | 7.5 | 75 | NO | YES |
CVE-2013-10042CRITICAL A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PASS command. When an attacker sends a specially crafted passwo | Jul 31, 2025 | 9.8 | 42 | NO | YES |
CVE-2005-3684HIGH Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute ar | Nov 19, 2005 | 7.5 | 36 | NO | YES |
CVE-2012-6067HIGH freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of | Dec 4, 2012 | 10.0 | 30 | NO | NO |
CVE-2005-3812MEDIUM freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments. | Nov 26, 2005 | 6.8 | 29 | NO | YES |
CVE-2019-19383HIGH freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled). | Dec 3, 2019 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeftpd.
Media articles that mention a CVE ID that affects a product developed by Freeftpd — matched by CVE ID, not by vendor name.