Maxum Development Corporation maintains Rumpus FTP Server, a niche file-transfer product with a modest but durable vulnerability footprint. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of legacy FTP infrastructure as a target for automation and mass scanning. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxum Development Corporation over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0019MEDIUM Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecifi | Jan 19, 2007 | 6.5 | 27 | NO | YES |
CVE-2001-0646MEDIUM Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length. | Sep 20, 2001 | 5.0 | 23 | NO | YES |
CVE-2001-0644HIGH Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges o | Sep 20, 2001 | 7.5 | 19 | NO | NO |
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders. | Sep 20, 2001 | 2.1 | 17 | NO | YES |
CVE-2007-0366MEDIUM Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program. | Jan 19, 2007 | 4.6 | 14 | NO | NO |
CVE-2007-0367MEDIUM Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown | Jan 19, 2007 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxum Development Corporation.
Media articles that mention a CVE ID that affects a product developed by Maxum Development Corporation — matched by CVE ID, not by vendor name.