Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v5vr-r7j6-q2w6

Опубликовано: 05 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 9.8

Описание

A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.

A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.

EPSS

Процентиль: 99%
0.70595
Высокий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.

EPSS

Процентиль: 99%
0.70595
Высокий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-121