Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-5323 | Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to the PWD command, the client fails to properly validate the length of the input before copying it into a fixed-size buffer. This results in memory corruption and allows remote attackers to execute arbitrary code on the client system. |
Thu, 20 Nov 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:netsarang:xftp:*:*:*:*:*:*:*:* |
Tue, 26 Aug 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netsarang
Netsarang xftp |
|
| Vendors & Products |
Netsarang
Netsarang xftp |
Thu, 21 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to the PWD command, the client fails to properly validate the length of the input before copying it into a fixed-size buffer. This results in memory corruption and allows remote attackers to execute arbitrary code on the client system. | |
| Title | Xftp FTP Client <= 3.0 PWD Response Buffer Overflow | |
| Weaknesses | CWE-121 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:13:37.303Z
Reserved: 2025-08-20T20:33:55.844Z
Link: CVE-2010-20122
Updated: 2025-08-21T20:28:49.148Z
Status : Deferred
Published: 2025-08-21T21:15:34.680
Modified: 2026-04-15T00:35:42.020
Link: CVE-2010-20122
No data.
OpenCVE Enrichment
Updated: 2025-08-26T08:54:56Z
EUVD