Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pureftpd

First CVE: Aug 6, 2004Active for: 22 yearsTotal CVEs: 12
51.1
VTI Score
TOP TARGET

Pure-FTPd is a lightweight, widely deployed FTP server implementation that has occupied a prominent position in file-transfer infrastructure despite its focused scope. Vulnerabilities in this vendor center on memory-safety and input-handling issues—out-of-bounds reads, uninitialized pointer accesses, path traversal, and resource-exhaustion conditions—that are characteristic of network daemons handling untrusted protocol input, and the vendor's disclosures have frequently acquired public exploit tooling. Defenders should treat this vendor's releases as a patching priority for exposed FTP services and monitor for exploit availability in security bulletins; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pureftpd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2004
21 years ago
Most Recent CVE
Oct 24, 2024
637 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-40524HIGH
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a ser
Sep 5, 20217.537NOYES
CVE-2020-9274HIGH
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri
Feb 26, 20207.537NOYES
CVE-2019-20176HIGH
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
Dec 31, 20197.537NOYES
CVE-2020-9365HIGH
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
Feb 24, 20207.536NOYES
CVE-2020-35359HIGH
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
Dec 26, 20207.535NOYES
CVE-2011-1575MEDIUM
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into en
May 23, 20115.835NONO
CVE-2024-48208HIGH
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
Oct 24, 20248.632NOYES
CVE-2011-0418MEDIUM
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated use
May 24, 20114.029NOYES
CVE-2017-12170CRITICAL
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started
Sep 21, 20179.824NONO
CVE-2004-0656MEDIUM
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
Aug 6, 20045.024NOYES
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
33%
50%
8%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (58.3%)
Unknown5 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (58.3%)
High0 (0.0%)
Unknown5 (41.7%)
User Interaction
None7 (58.3%)
Unknown5 (41.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (58.3%)
Unknown5 (41.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
8 CVEs
66.7% of CVEs· 99th percentile
ExploitDB
1 CVE
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pureftpd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pureftpd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pureftpd's Products

View all 3 CNAs →

Top CWEs