Pure-FTPd is a lightweight, widely deployed FTP server implementation that has occupied a prominent position in file-transfer infrastructure despite its focused scope. Vulnerabilities in this vendor center on memory-safety and input-handling issues—out-of-bounds reads, uninitialized pointer accesses, path traversal, and resource-exhaustion conditions—that are characteristic of network daemons handling untrusted protocol input, and the vendor's disclosures have frequently acquired public exploit tooling. Defenders should treat this vendor's releases as a patching priority for exposed FTP services and monitor for exploit availability in security bulletins; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pureftpd over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40524HIGH In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a ser | Sep 5, 2021 | 7.5 | 37 | NO | YES |
CVE-2020-9274HIGH An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri | Feb 26, 2020 | 7.5 | 37 | NO | YES |
CVE-2019-20176HIGH In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. | Dec 31, 2019 | 7.5 | 37 | NO | YES |
CVE-2020-9365HIGH An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c. | Feb 24, 2020 | 7.5 | 36 | NO | YES |
CVE-2020-35359HIGH Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit. | Dec 26, 2020 | 7.5 | 35 | NO | YES |
CVE-2011-1575MEDIUM The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into en | May 23, 2011 | 5.8 | 35 | NO | NO |
CVE-2024-48208HIGH pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file. | Oct 24, 2024 | 8.6 | 32 | NO | YES |
CVE-2011-0418MEDIUM The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated use | May 24, 2011 | 4.0 | 29 | NO | YES |
CVE-2017-12170CRITICAL Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started | Sep 21, 2017 | 9.8 | 24 | NO | NO |
CVE-2004-0656MEDIUM The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections. | Aug 6, 2004 | 5.0 | 24 | NO | YES |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pureftpd.
Media articles that mention a CVE ID that affects a product developed by Pureftpd — matched by CVE ID, not by vendor name.