Pure Ftpd

Vendor:

First CVE: Aug 6, 2004 · Active for 21 years

12
Total CVEs
More Total CVEs than 90% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pure Ftpd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2004
21 years ago
Most Recent CVE
Oct 24, 2024
642 days ago

CVE Severity & Scoring

Pure Ftpd12 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (58.3%)
Unknown5 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (58.3%)
High0 (0.0%)
Unknown5 (41.7%)
User Interaction
None7 (58.3%)
Unknown5 (41.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (58.3%)
Unknown5 (41.7%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a ser
Sep 5, 20217.537NOYES
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri
Feb 26, 20207.537NOYES
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
Dec 31, 20197.537NOYES
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
Feb 24, 20207.536NOYES
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
Dec 26, 20207.535NOYES
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into en
May 23, 20115.835NONO
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
Oct 24, 20248.632NOYES
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated use
May 24, 20114.029NOYES
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started
Sep 21, 20179.824NONO
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
Aug 6, 20045.024NOYES

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
8 CVEs
66.7% of CVEs· 99th percentile
ExploitDB
1 CVE
8.3% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Pure Ftpd

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.0.934.513.7%02
1.0.834.513.7%02
1.0.734.513.7%02
1.0.634.513.7%02
1.0.544.610.9%03
1.0.4927.55.7%02
1.0.4817.54.7%01
1.0.46-119.81.5%00
1.0.444.610.9%03
1.0.3014.07.3%01
1.0.344.610.9%03
1.0.2914.07.3%01
1.0.2824.920.3%01
1.0.2724.920.3%01
1.0.2624.920.3%01
1.0.2524.920.3%01
1.0.2424.920.3%01
1.0.2234.713.7%01
1.0.2134.513.7%02
1.0.2034.513.7%02