Glftpd is a specialized FTP server software with a narrow but persistent presence in the landscape, particularly in legacy and niche deployment contexts. The recurring vulnerability signal centers on resource-management issues such as allocation without limits or throttling, typical of protocol daemons handling concurrent connections, and the vendor's disclosures frequently acquire public exploit code. Defenders running this software should prioritize updates and monitor for resource exhaustion attack patterns; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Glftpd over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0038HIGH glFtpD includes a default glftpd user account with a default password and a UID of 0. | Dec 23, 1999 | 7.5 | 32 | NO | YES |
CVE-2021-31645HIGH An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit. | Jul 7, 2022 | 7.5 | 26 | NO | NO |
CVE-2000-0587HIGH The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability. | Jun 26, 2000 | 10.0 | 26 | NO | NO |
CVE-2001-0965MEDIUM glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters. | Aug 31, 2001 | 5.0 | 25 | NO | YES |
CVE-2000-0040HIGH glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command. | Dec 23, 1999 | 10.0 | 25 | NO | NO |
CVE-2006-1253HIGH Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address. | Mar 19, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-0483MEDIUM Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence | Mar 30, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Glftpd.
Media articles that mention a CVE ID that affects a product developed by Glftpd — matched by CVE ID, not by vendor name.