本页列出影响 ipswitch ws_ftp_pro 的已公开 CVE 漏洞(通过 NVD CPE 关联)。每行包含严重程度评分、摘要与发布日期,便于识别与分析安全问题。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2008-3734 | Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response). | [email protected] | 9.3 | 13.95% | 2008-08-20 | 2026-06-16 |
| CVE-2007-0665 | Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command. | [email protected] | 6.8 | 3.17% | 2007-02-02 | 2026-06-16 |
| CVE-2007-0330 | Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors. | [email protected] | 7.5 | 3.42% | 2007-01-17 | 2026-06-16 |
| CVE-2004-1884 | Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access. | [email protected] | 7.5 | 5.80% | 2004-03-23 | 2026-06-16 |
| CVE-2002-1851 | Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors. | [email protected] | 7.5 | 3.18% | 2002-12-31 | 2026-06-16 |
| CVE-1999-1078 | WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges. | [email protected] | 7.5 | 1.80% | 1999-07-29 | 2026-06-16 |