← Vulnerability feed

Vulnerability record · CVE-2021-31645 · published 7 July 2022

CVE-2021-31645: Glftpd allocation without limits vulnerability

Glftpd · Glftpd

An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.

7.5 CVSS 3.1 High EPSS 2.0% · top 20.5% CWE-770 · Allocation without limits
7.5CVSS 3.1 base score, v2 5.0
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://glftpd.io/ Vendor Advisory
https://www.exploit-db.com/exploits/49773 ExploitThird Party AdvisoryVDB Entry
https://glftpd.io/ Vendor Advisory
https://www.exploit-db.com/exploits/49773 ExploitThird Party AdvisoryVDB Entry

Track CVE-2021-31645 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2000-0587Glftpd vulnerabilityThe privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capabil…EPSS 4.2%10.0CVE-2000-0040Glftpd vulnerabilityglFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.EPSS 1.9%7.5CVE-2006-1253Glftpd vulnerabilityUnspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that …EPSS 1.5%7.5CVE-2000-0038Glftpd vulnerabilityglFtpD includes a default glftpd user account with a default password and a UID of 0.EPSS 6.6%5.0CVE-2005-0483Glftpd vulnerabilityMultiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users…EPSS 2.0%5.0CVE-2001-0965Glftpd vulnerabilityglFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number o…EPSS 7.1%8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2021-31645), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.