CVE-2020-37155High· 7.5▾ MidnightPoC availableCore FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.4%
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction.
lite 1.3c Build 1437Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-37070Critical· 9.8CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)
CVE-2020-37166Medium· 6.2AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service
CVE-2020-37164Medium· 6.2AbsoluteTelnet 11.12 - "license entry" Denial of Service
CVE-2020-37165Medium· 6.2AbsoluteTelnet 11.12 - "license name" Denial of Service
CVE-2025-14708Critical· 9.8A weakness has been identified in Shiguangwu sgwbox N3 2.0.25
CVE-2026-102296Medium· 6.5ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers.…