Tinyftp Project maintains a minimal FTP server implementation, a narrowly scoped product that occupies a legacy niche in file-transfer infrastructure. The durable signal in its disclosure history centers on memory-safety issues, specifically improper restriction of operations within memory buffer bounds, which reflects the parser-intensive and resource-constrained nature of embedded server code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinyftp Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0541CRITICAL Buffer overflow in Tiny FTP Daemon Ver0.52d allows an attacker to cause a denial-of-service (DoS) condition or execute arbitrary code via unspecified vectors. | Mar 22, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-17106HIGH In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An attacker can overwrite ebp via a long pathname. | Sep 16, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinyftp Project.
Media articles that mention a CVE ID that affects a product developed by Tinyftp Project — matched by CVE ID, not by vendor name.