This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2024-11-27 06:34:59 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
---|---|
29b7e3f4-b6a9-11df-ae63-f255a795cb21 | lftp -- multiple HTTP client download filename vulnerability The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory. Discovery 2010-06-09 Entry 2010-09-03 lftp < 4.0.6 CVE-2010-2251 https://bugzilla.redhat.com/show_bug.cgi?id=591580 |
d7af61c8-2cc0-11d8-9355-0020ed76ef5a | lftp HTML parsing vulnerability A buffer overflow exists in lftp which may be triggered when requesting a directory listing from a malicious server over HTTP. Discovery 2003-12-11 Entry 2003-12-12 lftp <= 2.6.10 CVE-2003-0963 http://lftp.yar.ru/news.html#2.6.10 |