VDB

CVE-2010-4221

CVE-2010-4221 PUBLISHED CVSS 10 CRITICAL

Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.

EPSS 92.05% · 99.7th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
92.05%
99.7th percentile

Affected Products

VendorProductVersions
n/an/a*
proftpdproftpd1.3.2, 1.3.2, 1.3.2

Timeline

  • Nov 9, 2010 CVE Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 17, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Jul 2, 2024 EPSS Score
  • Aug 7, 2024 CVE Updated
  • Dec 17, 2024 EPSS Score
  • Dec 27, 2024 EPSS Score
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Mar 17, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›