G.rodola

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-3494

    Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

    Last Modified: Apr 11, 2025
    Published: Oct 19, 2010

    CVE-2007-6736

    Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) in a (1) LIST, (2) STOR, or (3) RETR command.

    Last Modified: Apr 11, 2025
    Published: Oct 19, 2010

    CVE-2007-6737

    FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Last Modified: Apr 11, 2025
    Published: Oct 19, 2010

    CVE-2007-6738

    pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

    Last Modified: Apr 11, 2025
    Published: Oct 19, 2010

    CVE-2009-5010

    Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, a different vulnerability than CVE-2010-3494.

    Last Modified: Apr 11, 2025
    Published: Oct 19, 2010
    Items Per Page
    G.rodola Vulnerabilities & Security CVEs | CVE-DB