CVE-2005-0312
Last modified
CVE-2005-0312 is a vulnerability of currently unknown severity. WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.. EPSS estimates a 2.73% chance of exploitation in the next 30 days.
Description
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| War Ftp Daemon | War Ftp Daemon | 1.8 |
| War Ftp Daemon | War Ftp Daemon | 1.82_rc9 |
References
- http://support.jgaa.com/index.php?cmd=ShowReport&ID=02643Vendor Advisory
- http://www.securityfocus.com/bid/12384Patch, Vendor Advisory
- http://support.jgaa.com/index.php?cmd=ShowReport&ID=02643Vendor Advisory
- http://www.securityfocus.com/bid/12384Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0312?
How severe is CVE-2005-0312?
How do I fix CVE-2005-0312?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0306MercuryBoard 1.1.1 allows remote attackers to gain sensitive…
- CVE-2005-0307Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2005-0308Buffer overflow in the wsprintf function in W32Dasm 8.93 and…
- CVE-2005-0309Multiple cross-site scripting (XSS) vulnerabilities in (1) i…
- CVE-2005-0310Exponent 0.95 allows remote attackers to obtain sensitive in…
- CVE-2005-0311Ingate Firewall 4.1.3 and earlier does not terminate the PPT…
- CVE-2005-0313Multiple directory traversal vulnerabilities in Magic Winmai…
- CVE-2005-0314Cross-site scripting (XSS) vulnerability in user.php in Magi…
- CVE-2005-0315The FTP service in Magic Winmail Server 4.0 Build 1112 does …
- CVE-2005-0316WebWasher Classic 2.2.1 and 3.3, when running in server mode…
- CVE-2005-0317Cross-site scripting (XSS) vulnerability in useredit_account…
- CVE-2005-0318useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not proper…
Are you affected by CVE-2005-0312?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
