Aggregates CVE and security vulnerability intelligence across all hfiref0x-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk buffer overflow, vendor risk path handling, and vendor risk denial of service; exposure may include vendor impact application crash in vendor surface production workloads contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-65403 | A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | [email protected] | 6.5 | 0.05% | 2025-12-01 | 2025-12-05 |
| CVE-2023-24042 | A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName. | [email protected] | 7.5 | 0.30% | 2023-01-21 | 2025-12-08 |
| CVE-2017-1000218 | LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution. | [email protected] | 9.8 | 2.33% | 2017-11-17 | 2026-05-13 |