A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 23 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Pcman Ftp Server Project
Pcman Ftp Server Project pcman Ftp Server
CPEs cpe:2.3:a:pcman_ftp_server_project:pcman_ftp_server:2.0.7:*:*:*:*:*:*:*
Vendors & Products Pcman Ftp Server Project
Pcman Ftp Server Project pcman Ftp Server

Fri, 30 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 May 2025 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title PCMan FTP Server NLST Command buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-29T22:00:07.544Z

Updated: 2025-05-30T13:41:27.680Z

Reserved: 2025-05-29T10:02:58.803Z

Link: CVE-2025-5331

cve-icon Vulnrichment

Updated: 2025-05-30T13:41:11.728Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-29T22:15:22.940

Modified: 2025-06-23T14:35:13.397

Link: CVE-2025-5331

cve-icon Redhat

No data.