← All CVEs

CVE-2006-6565

medium · 4

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

4
CVSS
70.6%
EPSS (exploit prob.)
99th
EPSS percentile
2006-12-15
Published

AV:N/AC:L/Au:S/C:N/I:N/A:P

Weaknesses

CWE-476

Affected products

VendorProductAffected versions
filezilla-projectfilezilla_server< 0.9.22

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-6565