Page 2 of 7 results (0.005 seconds)

CVSS: 5.0EPSS: 18%CPEs: 2EXPL: 0

vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant. • ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-1.2.2/Changelog http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=119136 http://rhn.redhat.com/errata/RHBA-2004-164.html http://secunia.com/advisories/11680 http://secunia.com/advisories/11736 http://www.osvdb.org/6306 http://www.securityfocus.com/bid/10394 https://exchange.xforce.ibmcloud.com/vulnerabilities/16222 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11049 •

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 0

vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames. vsftpd 1.1.3 genera diferentes mensajes de error dependiendo de si existe o no un nombre de usuario válido, lo que permite que atacantes remotos identifiquen nombres de usuarios válidos. • http://securitytracker.com/id?1008628 •