{"api_version":"1","generated_at":"2026-07-23T07:42:38+00:00","cve":"CVE-2007-1731","urls":{"html":"https://cve.report/CVE-2007-1731","api":"https://cve.report/api/cve/CVE-2007-1731.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1731","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1731"},"summary":{"title":"CVE-2007-1731","description":"Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-03-28 10:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/23147","name":"http://www.securityfocus.com/bid/23147","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"High Performance Anonymous FTP Server Multiple Remote Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securiteam.com/securitynews/5AP0L1PKUU.html","name":"http://www.securiteam.com/securitynews/5AP0L1PKUU.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecuriTeam - hpaftpd Multiple Buffer Overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33288","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1142","name":"http://www.vupen.com/english/advisories/2007/1142","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/35182","name":"http://osvdb.org/35182","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1731","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1731","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1731","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hpaftpd","cpe5":"hpaftpd","cpe6":"1.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:06:26.098Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-1142","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1142"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securiteam.com/securitynews/5AP0L1PKUU.html"},{"name":"23147","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23147"},{"name":"35182","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35182"},{"name":"hpaftpd-multiple-commands-bo(33288)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33288"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-03-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-1142","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1142"},{"tags":["x_refsource_MISC"],"url":"http://www.securiteam.com/securitynews/5AP0L1PKUU.html"},{"name":"23147","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23147"},{"name":"35182","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35182"},{"name":"hpaftpd-multiple-commands-bo(33288)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33288"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1731","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-1142","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1142"},{"name":"http://www.securiteam.com/securitynews/5AP0L1PKUU.html","refsource":"MISC","url":"http://www.securiteam.com/securitynews/5AP0L1PKUU.html"},{"name":"23147","refsource":"BID","url":"http://www.securityfocus.com/bid/23147"},{"name":"35182","refsource":"OSVDB","url":"http://osvdb.org/35182"},{"name":"hpaftpd-multiple-commands-bo(33288)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33288"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1731","datePublished":"2007-03-28T10:00:00.000Z","dateReserved":"2007-03-27T00:00:00.000Z","dateUpdated":"2024-08-07T13:06:26.098Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-28 10:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hpaftpd:hpaftpd:1.01:*:*:*:*:*:*:*","matchCriteriaId":"D977A544-2ADE-4C5D-A43F-B6E0B3155B90"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1731","Ordinal":"1","Title":"CVE-2007-1731","CVE":"CVE-2007-1731","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1731","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command.","Type":"Description","Title":"CVE-2007-1731"},{"CveYear":"2007","CveId":"1731","Ordinal":"2","NoteData":"2007-03-28","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1731","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}