
CVE-2004-1485
https://notcve.org/view.php?id=CVE-2004-1485
31 Dec 2004 — Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function. • http://marc.info/?l=bugtraq&m=109882085912915&w=2 •

CVE-2002-2237
https://notcve.org/view.php?id=CVE-2002-2237
31 Dec 2002 — tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux. • http://archives.neohapsis.com/archives/bugtraq/2002-12/0084.html • CWE-20: Improper Input Validation •

CVE-1999-0183
https://notcve.org/view.php?id=CVE-1999-0183
01 Sep 1997 — Linux implementations of TFTP would allow access to files outside the restricted directory. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0183 •