Jgaa's vulnerability profile centers on WarFTPD, a legacy file-transfer server whose exposure reflects the characteristic weaknesses of older FTP implementations. The recurring technical signals include format-string vulnerabilities and input-validation issues that are endemic to protocol parsers built without modern memory-safety disciplines, and the vendor's disclosures have acquired public exploit code. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jgaa over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0256HIGH Buffer overflow in War FTP allows remote execution of commands. | Feb 1, 1998 | 7.5 | 77 | NO | YES |
CVE-2000-0131MEDIUM Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands. | Feb 1, 2000 | 5.0 | 27 | NO | YES |
CVE-2013-2278HIGH Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (crash) and possibly execute arb | Apr 1, 2014 | 10.0 | 25 | NO | NO |
CVE-2009-5141MEDIUM Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST com | Apr 1, 2014 | 4.0 | 25 | NO | YES |
CVE-2000-0044HIGH Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands. | Jan 6, 2000 | 10.0 | 25 | NO | NO |
CVE-2006-5789MEDIUM War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) N | Nov 7, 2006 | 4.0 | 21 | NO | YES |
CVE-2006-2171MEDIUM Buffer overflow in WDM.exe in WarFTPD allows remote attackers to execute arbitrary code via unspecified arguments, as demonstrated by the Infigo FTPStress Fuzzer. | May 4, 2006 | 6.4 | 20 | NO | NO |
CVE-1999-1003MEDIUM War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections. | Dec 13, 1999 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jgaa.
Media articles that mention a CVE ID that affects a product developed by Jgaa — matched by CVE ID, not by vendor name.