globalscape 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
公開された問題は パス処理の欠陥 and バッファオーバーフロー に関連することが多く、vendor surface software deployment and vendor surface production workloads の文脈で アプリケーションクラッシュ and vendor impact memory corruption などの暴露リスクを伴う場合があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2024-1190 | A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252680. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | [email protected] | 3.3 | 0.02% | 2024-02-02 | 2024-11-21 |
| CVE-2023-2991 | Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message | [email protected] | 5.3 | 0.27% | 2023-06-22 | 2024-11-21 |
| CVE-2023-2990 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service | [email protected] | 7.5 | 0.16% | 2023-06-22 | 2024-11-21 |
| CVE-2023-2989 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited | [email protected] | 9.1 | 0.07% | 2023-06-22 | 2024-11-21 |
| CVE-2009-3483 | Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a site list containing an entry with a long label. | [email protected] | 9.3 | 2.62% | 2009-09-30 | 2026-04-23 |
| CVE-2008-2779 | Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder. | [email protected] | 9.3 | 0.31% | 2008-06-19 | 2026-04-23 |
| CVE-2006-1693 | Unspecified vulnerability in GlobalSCAPE Secure FTP Server before 3.1.4 Build 01.10.2006 allows attackers to cause a denial of service (application crash) via a "custom command" with a long argument. | [email protected] | 5.0 | 0.51% | 2006-04-11 | 2026-04-16 |
| CVE-2005-1415 | Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command. | [email protected] | 10.0 | 67.94% | 2005-05-03 | 2026-04-16 |
| CVE-2004-1136 | Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands. | [email protected] | 5.0 | 0.50% | 2005-01-10 | 2026-04-16 |
| CVE-2004-2366 | Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument. | [email protected] | 5.0 | 3.53% | 2004-12-31 | 2026-04-16 |
| CVE-2003-1261 | Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard. | [email protected] | 2.1 | 0.07% | 2003-12-31 | 2026-04-16 |
| CVE-2003-1260 | Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command. | [email protected] | 7.6 | 23.02% | 2003-12-31 | 2026-04-16 |
| CVE-2000-0084 | CuteFTP uses weak encryption to store password information in its tree.dat file. | [email protected] | 5.0 | 0.33% | 2000-01-06 | 2026-04-16 |