Vulnerabilities (CVE)

Filtered by vendor Netbsd Subscribe
Filtered by product Ftpd
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2245 1 Netbsd 1 Ftpd 2024-11-20 5.0 MEDIUM N/A
ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.
CVE-2023-45198 1 Netbsd 2 Ftpd, Tnftpd 2024-02-28 N/A 7.5 HIGH
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.