← Vulnerability feed

Vulnerability record · CVE-2008-3734 · published 20 August 2008

CVE-2008-3734: Ipswitch ws ftp home vulnerability

Ipswitch · Ws Ftp Home

Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).

9.3 CVSS 2.0 High EPSS 14% · top 3.6% CWE-134 · CWE-134
9.3CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3734 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3795Ipswitch ws ftp home memory buffer overflow vulnerabilityBuffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response."EPSS 15%7.5CVE-2007-0330Ipswitch ws ftp pro vulnerabilityBuffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (…EPSS 3.4%7.5CVE-2004-1884Ipswitch ws ftp pro vulnerabilityIpswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.EPSS 5.8%7.5CVE-2002-1851Ipswitch ws ftp pro vulnerabilityBuffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.EPSS 3.4%7.5CVE-1999-1078Ipswitch ws ftp pro vulnerabilityWS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain…EPSS 1.8%6.8CVE-2007-0665Ipswitch ws ftp pro vulnerabilityFormat string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via for…EPSS 3.3%9.8CVE-2024-23113Fortinet FortiOS and related products format string remote code executionA use of externally-controlled format string (CWE-134) in Fortinet FortiOS, FortiProxy, FortiPAM and FortiSwitchManager lets an attacker execute unau…KEVEPSS 62%analysed5.5CVE-2021-25489Samsung Android modem driver format string bug causes kernel panicSamsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA…KEVEPSS 0.53%analysed

Source: NIST National Vulnerability Database (record CVE-2008-3734), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.