Open TFTP Server Project maintains a narrowly scoped TFTP file-transfer utility that, despite limited product scope, has exhibited vulnerabilities skewing strongly toward critical severity, primarily rooted in memory-safety and access-control weaknesses. The recurring exposure centers on out-of-bounds writes, format-string mishandling, and improper permission assignment across the core server implementation, typical of C-based network utilities handling untrusted file-transfer requests. Defenders should treat this vendor's advisories as requiring urgent review due to the severity profile; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Tftp Server Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12568CRITICAL Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code | Dec 23, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-10388CRITICAL Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format s | Dec 23, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-10389CRITICAL Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format s | Dec 23, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-10387CRITICAL Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error | Dec 23, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-12567CRITICAL Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code | Dec 23, 2019 | 9.8 | 28 | NO | NO |
CVE-2020-26130HIGH Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, | Oct 28, 2020 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Tftp Server Project.
Media articles that mention a CVE ID that affects a product developed by Open Tftp Server Project — matched by CVE ID, not by vendor name.