Whitsoft Development maintains SlimFTPD, a lightweight FTP server product whose narrow scope belies its presence across embedded and resource-constrained deployments. The observed vulnerability signal centers on the FTP server's protocol-parsing and input-handling surface, reflected in the classified weaknesses. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whitsoft Development over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2373HIGH Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands. | Jul 26, 2005 | 7.2 | 61 | NO | YES |
CVE-2004-2418HIGH Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT. | Dec 31, 2004 | 7.2 | 27 | NO | YES |
CVE-2005-2850MEDIUM SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error. | Sep 8, 2005 | 5.0 | 25 | NO | YES |
CVE-2001-1131MEDIUM Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command. | Aug 21, 2001 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whitsoft Development.
Media articles that mention a CVE ID that affects a product developed by Whitsoft Development — matched by CVE ID, not by vendor name.