← Back

Tnftpd

tnftpd

Vendor: Netbsd • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netbsd
2Ftpd
Tnftpd
Jun 17, 2026
Oct 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
1Netbsd
1Tnftpd
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a craf...Show more
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.Show less