Freesshd is a lightweight SSH and FTP server aimed at Windows environments, with a narrow but established user base spanning administrative and embedded deployment contexts. Its vulnerabilities cluster around memory-safety and authentication boundaries—including buffer overflows, unquoted search paths, improper authentication, and privilege-management flaws—and the vendor's disclosures have a strong tendency to acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freesshd over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2407HIGH Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, all | May 16, 2006 | 7.5 | 75 | NO | YES |
CVE-2012-6066HIGH freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c | Dec 4, 2012 | 9.3 | 71 | NO | YES |
CVE-2008-4762HIGH Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argum | Oct 28, 2008 | 9.0 | 39 | NO | YES |
CVE-2008-6899HIGH Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a long (1) open, (2) unlink, (3) mk | Aug 5, 2009 | 9.0 | 34 | NO | YES |
CVE-2008-2573HIGH Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) comm | Jun 6, 2008 | 8.5 | 33 | NO | YES |
CVE-2024-0723HIGH A vulnerability was found in freeSSHd 1.0.9 on Windows. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service. It is poss | Jan 19, 2024 | 7.5 | 32 | NO | YES |
CVE-2018-9853CRITICAL Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to login to an unprivileged accoun | Jul 10, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-1000475HIGH FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges. | Jan 24, 2018 | 7.8 | 24 | NO | NO |
CVE-2008-0852MEDIUM freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference. | Feb 21, 2008 | 5.0 | 24 | NO | YES |
CVE-2022-27052HIGH FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. | Mar 31, 2022 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freesshd.
Media articles that mention a CVE ID that affects a product developed by Freesshd — matched by CVE ID, not by vendor name.