Page 48 of 256 results (0.008 seconds)

CVSS: 5.0EPSS: 0%CPEs: 24EXPL: 0

Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command. Rhino Software Serv-U v7.0.0.1 a v8.2.0.3 permite a atacantes remotos causar una denegación de servicio (mediante caída del servidor) a través de vectores no especificados relacionados con el comando FTP "SITE SET TRANSFERPROGRESS ON". • http://secunia.com/advisories/36873 http://www.serv-u.com/releasenotes https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5798 •

CVSS: 5.0EPSS: 3%CPEs: 5EXPL: 3

SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information. SolarWinds TFTP Server v9.2.0.111 y anteriores permite a atacantes remotos provocar una denegación de servicio (parada del servicio) a través de una petición Option Acknowledgement (OACK) manipulada. NOTA: algunos de estos detalles han sido obtenidos a partir de información de terceros. • https://www.exploit-db.com/exploits/9547 http://secunia.com/advisories/36505 http://www.exploit-db.com/exploits/9547 http://www.securityfocus.com/bid/36182 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 76%CPEs: 14EXPL: 1

Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request. Vulnerabilidad de salto de directorio en el servidor FTP en Rhino Software Serv-U File Server v7.4.0.1 permite a atacantes remotos crear directorios de su elección a través de \.. (barra invertida punto punto) en una petición MKD. • https://www.exploit-db.com/exploits/8211 http://osvdb.org/52773 http://secunia.com/advisories/34329 http://www.securityfocus.com/bid/34125 http://www.vupen.com/english/advisories/2009/0738 https://exchange.xforce.ibmcloud.com/vulnerabilities/49258 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 4.0EPSS: 3%CPEs: 14EXPL: 1

The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument. El servidor FTP en Serv-U versiones 7.0.0.1 hasta 7.4.0.1, permite a los usuarios remotos autenticados causar una denegación de servicio (bloqueo de servicio) por medio de un gran número de comandos SMNT sin un argumento. • https://www.exploit-db.com/exploits/8212 http://www.securityfocus.com/bid/34127 https://exchange.xforce.ibmcloud.com/vulnerabilities/49260 • CWE-399: Resource Management Errors •

CVSS: 4.0EPSS: 1%CPEs: 12EXPL: 2

Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1". Serv-U v7.3, y v7.2.0.1 y anteriores, permite a usuarios autenticados en remoto provocar una denegación de servicio (consumo de la CPU) a través de un comando stou manipulado; probablemente está relacionado con los nombres de dispositivo de MS-DOS, como se ha demostrado usando "con:1" • https://www.exploit-db.com/exploits/6660 http://secunia.com/advisories/32150 http://securityreason.com/securityalert/4377 http://www.securityfocus.com/bid/31556 http://www.vupen.com/english/advisories/2008/2746 https://exchange.xforce.ibmcloud.com/vulnerabilities/45652 • CWE-20: Improper Input Validation •