Pure Ftpd
Vendor:
First CVE: Aug 6, 2004 · Active for 21 years
12
Total CVEs
More Total CVEs than 90% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pure Ftpd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2004
21 years ago
Most Recent CVE
Oct 24, 2024
642 days ago
CVE Severity & Scoring
Pure Ftpd12 CVEs
8%
33%
50%
8%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (58.3%)
Unknown5 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (58.3%)
High0 (0.0%)
Unknown5 (41.7%)
User Interaction
None7 (58.3%)
Unknown5 (41.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (58.3%)
Unknown5 (41.7%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40524HIGH In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a ser | Sep 5, 2021 | 7.5 | 37 | NO | YES |
CVE-2020-9274HIGH An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri | Feb 26, 2020 | 7.5 | 37 | NO | YES |
CVE-2019-20176HIGH In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. | Dec 31, 2019 | 7.5 | 37 | NO | YES |
CVE-2020-9365HIGH An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c. | Feb 24, 2020 | 7.5 | 36 | NO | YES |
CVE-2020-35359HIGH Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit. | Dec 26, 2020 | 7.5 | 35 | NO | YES |
CVE-2011-1575MEDIUM The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into en | May 23, 2011 | 5.8 | 35 | NO | NO |
CVE-2024-48208HIGH pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file. | Oct 24, 2024 | 8.6 | 32 | NO | YES |
CVE-2011-0418MEDIUM The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated use | May 24, 2011 | 4.0 | 29 | NO | YES |
CVE-2017-12170CRITICAL Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started | Sep 21, 2017 | 9.8 | 24 | NO | NO |
CVE-2004-0656MEDIUM The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections. | Aug 6, 2004 | 5.0 | 24 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
8 CVEs
66.7% of CVEs· 99th percentile
ExploitDB
1 CVE
8.3% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Pure Ftpd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.9 | 3 | 4.5 | 13.7% | 0 | 2 |
| 1.0.8 | 3 | 4.5 | 13.7% | 0 | 2 |
| 1.0.7 | 3 | 4.5 | 13.7% | 0 | 2 |
| 1.0.6 | 3 | 4.5 | 13.7% | 0 | 2 |
| 1.0.5 | 4 | 4.6 | 10.9% | 0 | 3 |
| 1.0.49 | 2 | 7.5 | 5.7% | 0 | 2 |
| 1.0.48 | 1 | 7.5 | 4.7% | 0 | 1 |
| 1.0.46-1 | 1 | 9.8 | 1.5% | 0 | 0 |
| 1.0.4 | 4 | 4.6 | 10.9% | 0 | 3 |
| 1.0.30 | 1 | 4.0 | 7.3% | 0 | 1 |
| 1.0.3 | 4 | 4.6 | 10.9% | 0 | 3 |
| 1.0.29 | 1 | 4.0 | 7.3% | 0 | 1 |
| 1.0.28 | 2 | 4.9 | 20.3% | 0 | 1 |
| 1.0.27 | 2 | 4.9 | 20.3% | 0 | 1 |
| 1.0.26 | 2 | 4.9 | 20.3% | 0 | 1 |
| 1.0.25 | 2 | 4.9 | 20.3% | 0 | 1 |
| 1.0.24 | 2 | 4.9 | 20.3% | 0 | 1 |
| 1.0.22 | 3 | 4.7 | 13.7% | 0 | 1 |
| 1.0.21 | 3 | 4.5 | 13.7% | 0 | 2 |
| 1.0.20 | 3 | 4.5 | 13.7% | 0 | 2 |