CVE-2000-0574

Exp

FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.

Published: 2000-07-07 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2000-0574 is rated High Exploit Risk (74.6/100): CVSS Medium severity, with high exploitation likelihood (EPSS 58.87%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +46.13% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2000-0574

EDB-ID Source Kind Published Link
396 exploit_db edb 2002-01-01 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2000-0574

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 12.74% 58.87% +46.13%
2 2025-03-30 20.46% 12.74% -7.72%
3 2025-03-29 20.46%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2000-0574

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2000-0574

Affected software / configurations for CVE-2000-0574

Vendor Product Version Raw CPE
openbsd ftpd 5.51 cpe:2.3:a:openbsd:ftpd:5.51:*:*:*:*:*:*:*
openbsd ftpd 5.60 cpe:2.3:a:openbsd:ftpd:5.60:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta1 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta1:*:academ:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18:*:academ:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr4 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr4:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr5 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr5:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr6 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr6:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr7 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr7:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr8 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr8:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr9 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr9:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr10 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr10:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr11 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr11:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr12 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr12:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr13 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr13:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr14 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr14:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_beta18_vr15 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr15:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_vr16 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr16:*:*:*:*:*:*:*
washington_university wu-ftpd 2.4.2_vr17 cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr17:*:*:*:*:*:*:*
washington_university wu-ftpd 2.5 cpe:2.3:a:washington_university:wu-ftpd:2.5:*:*:*:*:*:*:*
washington_university wu-ftpd 2.6 cpe:2.3:a:washington_university:wu-ftpd:2.6:*:*:*:*:*:*:*

References for CVE-2000-0574

cvelogic Threat Intelligence