Cuteftp

Vendor:

First CVE: Jan 6, 2000 · Active for 26 years

7
Total CVEs
More Total CVEs than 85% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 58% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cuteftp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 6, 2000
26 years ago
Most Recent CVE
Feb 2, 2024
907 days ago

CVE Severity & Scoring

Cuteftp7 CVEs
All CVEs353,240 CVEs
LowMediumHigh
Attack Vector
Local1 (14.3%)
Network0 (0.0%)
Unknown6 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (14.3%)
High0 (0.0%)
Unknown6 (85.7%)
User Interaction
None1 (14.3%)
Unknown6 (85.7%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (85.7%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
Dec 31, 20037.639NOYES
Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a
Sep 30, 20099.324NONO
Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arb
Jun 19, 20089.323NONO
A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host
Feb 2, 20245.520NONO
Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP comman
Jan 10, 20055.019NONO
CuteFTP uses weak encryption to store password information in its tree.dat file.
Jan 6, 20005.015NONO
Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.
Dec 31, 20032.114NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Cuteftp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.0.315.50.3%00
8.3.3.005419.34.7%00
8.3.319.34.7%00
8.2.019.32.6%00
6.015.01.1%00
5.0.112.10.5%00
5.024.84.6%01