โ† Back to all CVEs

CVE-2019-25614

CRITICAL freefloat NVD
CVSS Score 9.8
Severity CRITICAL
Published Mar 22, 2026
Vendor freefloat

Description

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

References