Serv U File Server

Vendor:

First CVE: Feb 16, 2001 · Active for 25 years

20
Total CVEs
More Total CVEs than 95% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Serv U File Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2001
25 years ago
Most Recent CVE
May 5, 2021
1,910 days ago

CVE Severity & Scoring

Serv U File Server20 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None0 (0.0%)
Unknown19 (95.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.0%)
Unknown19 (95.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbi
Nov 20, 200910.086NOYES
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
Dec 31, 20048.585NOYES
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.
Nov 23, 200410.085NOYES
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server usi
Dec 31, 200410.044NOYES
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a
Oct 9, 20089.041NOYES
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directorie
Dec 14, 20119.039NOYES
Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (
Mar 20, 20097.836NOYES
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as
Sep 11, 20045.033NOYES
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD
Feb 16, 20015.033NOYES
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
Apr 20, 20045.030NOYES

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
15.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
60.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Serv U File Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.4.0.219.08.4%01
9.4.0.019.08.4%01
9.3.0.119.08.4%01
9.2.0.119.08.4%01
9.1.0.226.55.6%01
9.1.0.037.731.4%02
9.0.0.537.731.4%02
9.0.0.337.731.4%02
9.0.0.137.731.4%02
8.2.0.347.024.6%02
8.2.0.147.024.6%02
8.2.0.047.024.6%02
8.1.0.347.024.6%02
8.1.0.147.024.6%02
8.0.0.747.024.6%02
8.0.0.547.024.6%02
8.0.0.447.024.6%02
8.0.0.247.024.6%02
8.0.0.147.024.6%02
7.4.0.166.619.4%04