Vulnerabilities (CVE)

Filtered by vendor Solarwinds Subscribe
Total 319 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1951 1 Solarwinds 1 Tftp Server 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.
CVE-2005-3467 1 Solarwinds 1 Serv-u File Server 2026-06-16 5.0 MEDIUM N/A
Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.
CVE-2004-2533 1 Solarwinds 1 Serv-u File Server 2026-06-16 5.0 MEDIUM N/A
Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.
CVE-2004-2532 1 Solarwinds 1 Serv-u File Server 2026-06-16 10.0 HIGH N/A
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.
CVE-2004-2111 1 Solarwinds 1 Serv-u File Server 2026-06-16 8.5 HIGH N/A
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
CVE-2004-1992 1 Solarwinds 1 Serv-u File Server 2026-06-16 5.0 MEDIUM N/A
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
CVE-2004-1852 1 Solarwinds 1 Dameware Mini Remote Control 2026-06-16 5.0 MEDIUM N/A
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
CVE-2004-1675 1 Solarwinds 1 Serv-u File Server 2026-06-16 5.0 MEDIUM N/A
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
CVE-2004-0330 1 Solarwinds 1 Serv-u File Server 2026-06-16 10.0 HIGH N/A
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.
CVE-2002-2393 1 Solarwinds 1 Serv-u File Server 2026-06-16 5.0 MEDIUM N/A
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.
CVE-2002-1542 1 Solarwinds 1 Tftp Server 2026-06-16 5.0 MEDIUM N/A
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
CVE-2002-1209 1 Solarwinds 1 Tftp Server 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
CVE-2001-1463 1 Solarwinds 1 Serv-u File Server 2026-06-16 7.5 HIGH N/A
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
CVE-2001-0054 1 Solarwinds 1 Serv-u File Server 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
CVE-2026-28318 1 Solarwinds 1 Serv-u 2026-06-05 N/A 7.5 HIGH
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
CVE-2026-28299 1 Solarwinds 1 Web Help Desk 2026-06-04 N/A 8.2 HIGH
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.
CVE-2018-25252 1 Solarwinds 1 Ftp Voyager 2026-04-20 N/A 6.2 MEDIUM
FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process.
CVE-2026-28298 1 Solarwinds 1 Observability Self-hosted 2026-03-31 N/A 5.9 MEDIUM
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
CVE-2026-28297 1 Solarwinds 1 Observability Self-hosted 2026-03-31 N/A 6.1 MEDIUM
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.