G.Rodola maintains pyftpdlib, a Python-based FTP server library that, despite limited product scope, occupies a niche in server implementations and integrations. The vendor's vulnerability surface centers on authentication bypass, race conditions in shared resource handling, path-traversal issues, and input-validation gaps that reflect the complexity of protocol-state management and file-system access control in an FTP daemon. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by G.Rodola over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7263HIGH ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute | Oct 19, 2010 | 7.5 | 22 | NO | NO |
CVE-2007-6737HIGH FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attacke | Oct 19, 2010 | 7.5 | 22 | NO | NO |
CVE-2008-7262MEDIUM Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involv | Oct 19, 2010 | 6.5 | 20 | NO | NO |
CVE-2007-6741MEDIUM The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of | Oct 19, 2010 | 6.5 | 20 | NO | NO |
CVE-2007-6736MEDIUM Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) | Oct 19, 2010 | 6.5 | 20 | NO | NO |
CVE-2007-6739MEDIUM FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command. | Oct 19, 2010 | 5.0 | 17 | NO | NO |
CVE-2007-6738MEDIUM pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive info | Oct 19, 2010 | 5.0 | 17 | NO | NO |
CVE-2010-3494MEDIUM Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immed | Oct 19, 2010 | 4.3 | 16 | NO | NO |
CVE-2009-5011MEDIUM Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immed | Oct 19, 2010 | 4.3 | 16 | NO | NO |
CVE-2009-5010MEDIUM Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immed | Oct 19, 2010 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by G.Rodola.
Media articles that mention a CVE ID that affects a product developed by G.Rodola — matched by CVE ID, not by vendor name.