Washington University's vulnerability footprint centers on WU-FTPD, a historically significant file-transfer daemon that, despite narrow product scope, achieved substantial deployment across Unix and Linux systems. The vendor's disclosures frequently acquire public exploit code, reflecting the product's role as a widely targeted network service and its presence in security research and defensive testing. Vulnerabilities recur through memory-safety weakness classes including buffer-boundary violations and improper memory operations, characteristic of legacy C-based network daemons. Defenders maintaining legacy Unix or Linux infrastructure should inventory WU-FTPD instances and treat this vendor's advisories as high-priority for internet-facing or untrusted-network deployments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Washington University over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0550HIGH wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob). | Nov 30, 2001 | 7.5 | 73 | NO | YES |
CVE-1999-0368HIGH Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Feb 9, 1999 | 10.0 | 60 | NO | YES |
CVE-2000-0574MEDIUM FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by | Jul 7, 2000 | 5.0 | 56 | NO | YES |
CVE-2001-0187HIGH Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that i | Mar 26, 2001 | 10.0 | 37 | NO | YES |
CVE-2004-0185HIGH Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code | Mar 15, 2004 | 10.0 | 27 | NO | NO |
CVE-1999-0080HIGH Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain r | Nov 30, 1995 | 10.0 | 27 | NO | NO |
CVE-2003-0853MEDIUM An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be r | Nov 17, 2003 | 5.0 | 26 | NO | YES |
CVE-1999-0878HIGH Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR. | Aug 22, 1999 | 10.0 | 25 | NO | NO |
CVE-2005-0256MEDIUM The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a larg | May 2, 2005 | 5.0 | 24 | NO | YES |
CVE-2003-1327HIGH Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow rem | Dec 31, 2003 | 9.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Washington University.
Media articles that mention a CVE ID that affects a product developed by Washington University — matched by CVE ID, not by vendor name.