Known Vulnerabilities for products from Filezilla-Project

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Filezilla-Project".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-53959 json FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a c... Not Provided 2025-12-19 2026-04-09
CVE-2023-48795 json 5.9 - MEDIUM 2023-12-18 2024-03-13
CVE-2022-29620 json ** DISPUTED ** FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory ... 6.5 - MEDIUM 2022-06-07 2023-11-07
CVE-2019-25683 json FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to ... Not Provided 2026-04-05 2026-04-09
CVE-2019-5429 json Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in... 7.8 - HIGH 2019-04-29 2023-11-07
CVE-2016-15003 json A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown... 7.8 - HIGH 2022-07-18 2022-07-25
CVE-2015-10003 json A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown par... 4.3 - MEDIUM 2022-07-17 2022-07-25
CVE-2014-0224 json OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpe... 7.4 - HIGH 2014-06-05 2023-11-07
CVE-2014-0160 json The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, w... Not Provided 2014-04-07 2026-04-21
CVE-2009-0884 json Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vector... 4.3 - MEDIUM 2009-03-12 2020-07-28
CVE-2006-6565 json FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1... 4 - MEDIUM 2006-12-15 2020-07-28
CVE-2005-0851 json FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service... Not Provided 2005-05-02 2025-04-03
CVE-2005-0850 json FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containin... Not Provided 2005-05-02 2025-04-03

Known software with vulnerabilities from Filezilla-Project

Type Vendor Product Version
ApplicationFilezilla-projectFilezilla3.40.0
ApplicationFilezilla-projectFilezilla Client3.0.0
ApplicationFilezilla-projectFilezilla Server0.9.21