Hfiref0x maintains a lightweight FTP server product that exhibits a durable vulnerability signal centered on memory-safety issues, including classic buffer overflows, race conditions, and improper memory-boundary restrictions. These weakness classes are characteristic of native-code network services and reflect the parsing and concurrency demands of FTP protocol handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hfiref0x over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000218CRITICAL LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution. | Nov 17, 2017 | 9.8 | 31 | NO | NO |
CVE-2023-24042HIGH A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName. | Jan 21, 2023 | 7.5 | 25 | NO | NO |
CVE-2025-65403MEDIUM A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Dec 1, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hfiref0x.
Media articles that mention a CVE ID that affects a product developed by Hfiref0x — matched by CVE ID, not by vendor name.