CVE Details
Basic Information
| Title | FreeFloat FTP Server XCWD Command buffer overflow |
|---|---|
| Type | cve |
| Published | 2025-06-05T15:00:18.109Z |
| Last Seen |
Product Information
| Vendor | FreeFloat |
|---|---|
| Product | FTP Server |
| Version | 1.0 |
CVSS Information
| Base Score | 6.9 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A buffer overflow vulnerability in FreeFloat FTP Server 1.0’s XCWD Command Handler allows remote attackers to cause a buffer overflow, potentially leading to system compromise. |
|---|---|
| AI Severity | Critical |
| Vendor | FreeFloat |
| Product | FreeFloat FTP Server |
| Affected Version | 1.0 |
Affected Products
- FreeFloat FTP Server 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-120, CWE-119 |
| Bulletin Family |
References
Description
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component XCWD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.