CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2223 | CVE-2000-0647 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-mlst-dos(5006) | View |
3117 | CVE-2001-0296 | Candidate | Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command. | Proposed (20010404) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Wall, Ziese | RECAST(1) Prosser | REVIEWING(1) Bishop | Frech> XF:wftpd-pro-cwd-bo(6184) | Prosser> See http://www.mail-archive.com/bugtraq@securityfocus.com/msg05671.html for additional info on this one. It looks like Can-2001-0296 may be a continuation of CVE 1999-0950. Appears from ref that this problem has been in every version since the 2.40 problem reported Oct 1999 (CVE 1999-0950). Just managed to change the code so it requires more characters to overflow the buffer. I haven"t tested this, but just from the available documentation, these problems look like a continuation of the early one. | View |
2221 | CVE-2000-0645 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE). | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-rest-dos(5004) | View |
2224 | CVE-2000-0648 | Candidate | WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, LeBlanc | REVIEWING(1) Wall | Frech> XF:wftpd-rnto-dos(4930) | View |
2222 | CVE-2000-0646 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-stat-info(5005) | View |
Page 20887 of 20943, showing 5 records out of 104715 total, starting on record 104431, ending on 104435