CVE-2014-4643
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 8.8%
from disclosure to weapon0 days
Published on NVDJun 25
1st PoCJun 11
exploitation probability
8.8%top 5% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/33713unverifiedexploitdbwww.exploit-db.com/exploits/33713unverifiedcve_referencepacketstormsecurity.com/files/127075/Core-FTP-LE-2.2-Heap-Overflow.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.