CVE-2025-5295CRITICAL 9.8EPSS p43.8%
CVE-2025-5295CVE-2025-5295
Description
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code of the component PORT Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.60% probability of exploitation · percentile 43.8% · 2026-06-19T12:03:05Z |
| Published | 2025-05-28 |
| Last modified | 2025-06-24 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 0% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.