← back
CVE-2009-4006

CVE-2009-4006

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 83%
from disclosure to weapon110 days
Published on NVDNov 20
1st PoC+110d
metasploitNov 1
exploitation probability
83%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.