Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 09 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xlightftpd xlight Ftp Server
|
|
| CPEs | cpe:2.3:a:xlightftpd:xlight_ftp_server:3.9.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Xlightftpd xlight Ftp Server
|
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration to trigger a buffer overflow that corrupts the SEH chain and enables potential code execution. | |
| Title | Xlight FTP Server 3.9.1 SEH Overwrite Buffer Overflow | |
| First Time appeared |
Xlightftpd
Xlightftpd xlight Ftp |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:xlightftpd:xlight_ftp:3.9.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Xlightftpd
Xlightftpd xlight Ftp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-06T18:24:46.806Z
Reserved: 2026-04-05T13:33:54.194Z
Link: CVE-2019-25681
Updated: 2026-04-06T18:24:38.514Z
Status : Analyzed
Published: 2026-04-05T21:16:46.457
Modified: 2026-04-09T19:33:14.990
Link: CVE-2019-25681
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:45:22Z