Known Vulnerabilities for Proftpd by Proftpd
Listed below are 10 of the newest known vulnerabilities associated with "Proftpd" by "Proftpd".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63091 json | ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record... | Not Provided | 2026-07-20 | 2026-07-28 |
| CVE-2026-63090 json | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows au... | Not Provided | 2026-07-20 | 2026-07-28 |
| CVE-2026-53994 json | ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() functio... | Not Provided | 2026-07-18 | 2026-07-28 |
| CVE-2026-42167 json | Not Provided | 2026-04-28 | 2026-07-24 | |
| CVE-2026-35025 json | ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to c... | Not Provided | 2026-06-24 | 2026-07-14 |
| CVE-2021-46854 json | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters. | 7.5 - HIGH | 2022-11-23 | 2023-05-03 |
| CVE-2020-9273 json | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-af... | 8.8 - HIGH | 2020-02-20 | 2023-11-07 |
| CVE-2020-9272 json | ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function. | 7.5 - HIGH | 2020-02-20 | 2021-11-09 |
| CVE-2019-19272 json | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initializ... | 7.5 - HIGH | 2019-11-26 | 2019-12-11 |
| CVE-2019-19271 json | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client ce... | 7.5 - HIGH | 2019-11-26 | 2019-12-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proftpd | Proftpd | 1.3.7 | |||
| Application | Proftpd | Proftpd | 1.3.7 | |||
| Application | Proftpd | Proftpd | 1.3.6c | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.6 | |||
| Application | Proftpd | Proftpd | 1.3.5e | |||
| Application | Proftpd | Proftpd | 1.3.5d | |||
| Application | Proftpd | Proftpd | 1.3.5c | |||
| Application | Proftpd | Proftpd | 1.3.5b | |||
| Application | Proftpd | Proftpd | 1.3.5a | |||
| Application | Proftpd | Proftpd | 1.3.5 | |||
| Application | Proftpd | Proftpd | 1.3.5 |