Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Fastream Subscribe
Total 11 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0255 1 Fastream 2 Fastream Ftp\+\+ Server, Fastream Ftp Server 2017-12-18 5.0 MEDIUM N/A
FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.
CVE-2001-0256 1 Fastream 1 Ftp\+\+ Server 2017-12-18 7.5 HIGH N/A
FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.
CVE-2000-0838 1 Fastream 1 Fur Http Server 2017-10-09 5.0 MEDIUM N/A
Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.
CVE-2004-1941 1 Fastream 1 Netfile Ftp Web Server 2017-07-10 5.0 MEDIUM N/A
Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.
CVE-2004-2534 1 Fastream 1 Netfile Server 2017-07-10 7.8 HIGH N/A
Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.
CVE-2004-0676 1 Fastream 1 Netfile Ftp Web Server 2017-07-10 10.0 HIGH N/A
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.
CVE-2004-0677 1 Fastream 1 Netfile Ftp Web Server 2017-07-10 5.0 MEDIUM N/A
Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A").
CVE-2003-1151 1 Fastream 1 Netfile Ftp Web Server 2017-07-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.
CVE-2001-0254 1 Fastream 1 Ftp\+\+ Server 2016-10-17 5.0 MEDIUM N/A
FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.
CVE-2005-1646 1 Fastream 1 Netfile Ftp Web Server 2011-03-07 7.5 HIGH N/A
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.
CVE-2000-0831 1 Fastream 1 Ftp\+\+ Server 2008-09-05 7.5 HIGH N/A
Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.