Winftp Server is a focused file-transfer product with a narrowly scoped vulnerability footprint centered on its single FTP server implementation. The observed disclosures reflect the general classification categories applied to this vendor; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winftp Server over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6673MEDIUM WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands. | Dec 21, 2006 | 5.0 | 23 | NO | YES |
CVE-2005-2634HIGH Buffer overflow in the Log-SCR function in the "Log to Screen" feature in WinFtp Server 1.6.8 allows remote attackers to cause a denial of service (application crash) and possibly | Aug 23, 2005 | 7.5 | 21 | NO | NO |
WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local users to gain access to the credentials. | Dec 31, 2004 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winftp Server.
Media articles that mention a CVE ID that affects a product developed by Winftp Server — matched by CVE ID, not by vendor name.