Miniftpd Project develops a lightweight FTP server implementation whose vulnerability footprint centers on classic buffer-overflow conditions in input handling. This niche product's exposure signal reflects the memory-safety demands inherent to a C-based network service; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miniftpd Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40239CRITICAL A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c | Oct 11, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-42624HIGH A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, where a crafted payload can be sent to the affected function. | Nov 4, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-39602MEDIUM A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a remote malicious user cause a Denial of Service. | Aug 23, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miniftpd Project.
Media articles that mention a CVE ID that affects a product developed by Miniftpd Project — matched by CVE ID, not by vendor name.