The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a denial of service (memory consumption) by engaging in client activity, such as establishing and then terminating a connection. This occurs because malloc is used but free is not.
📦
ftp
Vendor: chilkat_software
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
0
Remote Access
Total CVEs
1
Total Indexed
Avg. EPSS
16.25%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.5
CVSS
CVE-2023-22551
Exploit Found
Severity: HIGH
9.3
CVSS
CVE-2010-1465
Exploit Found
Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV response.
Severity: HIGH
7.5
CVSS
CVE-2008-4583
Exploit Found
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname in the SavePkcs8File method.
Severity: HIGH
0.0
CVSS