Iglooftp is a small file-transfer application with a narrow product portfolio comprising its standard and Pro offerings. The vendor's vulnerability disclosures reflect the straightforward nature of FTP server software, with the available evidence centered on generic weakness patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iglooftp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0561HIGH Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) P | Aug 18, 2003 | 7.5 | 35 | NO | YES |
CVE-2004-1277MEDIUM The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) ch | Jan 10, 2005 | 5.0 | 19 | NO | NO |
IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploaded by creating temporary files with names generated by the tm | Jan 10, 2005 | 2.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iglooftp.
Media articles that mention a CVE ID that affects a product developed by Iglooftp — matched by CVE ID, not by vendor name.