Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-5307 | Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service. |
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arcane Software
Arcane Software vermillion Ftp Daemon Microsoft Microsoft windows |
|
| Vendors & Products |
Arcane Software
Arcane Software vermillion Ftp Daemon Microsoft Microsoft windows |
Thu, 21 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service. | |
| Title | Vermillion FTP <= 1.31 Daemon PORT Command Memory Corruption | |
| Weaknesses | CWE-704 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:13:34.338Z
Reserved: 2025-08-20T18:52:46.120Z
Link: CVE-2010-20115
Updated: 2025-08-21T20:53:20.956Z
Status : Deferred
Published: 2025-08-21T21:15:34.313
Modified: 2026-04-15T00:35:42.020
Link: CVE-2010-20115
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:35Z
EUVD