← Vulnerability feed

Vulnerability record · CVE-2006-5789 · published 7 November 2006

CVE-2006-5789: Jgaa warftpd vulnerability

Jgaa · Warftpd

War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands. NOTE: it is possible that vector 1 is an off-by-one variant or incomplete fix of CVE-2005-0312.

4.0 CVSS 2.0 Medium EPSS 2.9% · top 13.5% CWE-399 · CWE-399
4.0CVSS 2.0 base score
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands. NOTE: it is possible that vector 1 is an off-by-one variant or incomplete fix of CVE-2005-0312.

AV:N/AC:L/Au:S/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5789 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-2278Jgaa warftpd vulnerabilityUnspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (…EPSS 3.5%10.0CVE-2000-0044Jgaa warftpd vulnerabilityMacros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.EPSS 3.1%7.5CVE-1999-0256War FTP buffer overflow allows remote command executionWar FTP contains a buffer overflow that lets a remote attacker execute commands. The flaw is network-reachable and requires no authentication, so any…EPSS 73%analysed6.4CVE-2006-2171Jgaa warftpd vulnerabilityBuffer overflow in WDM.exe in WarFTPD allows remote attackers to execute arbitrary code via unspecified arguments, as demonstrated by the Infigo FTPS…EPSS 4.6%5.0CVE-2000-0131Jgaa warftpd vulnerabilityBuffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.EPSS 7.6%5.0CVE-1999-1003Jgaa warftpd vulnerabilityWar FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.EPSS 1.9%4.0CVE-2009-5141Jgaa warftpd vulnerabilityFormat string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format …EPSS 2.7%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2006-5789), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.