CVE-2004-0255
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/11/2004
Last modified:
03/04/2025
Description
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:xlight_ftp_server:xlight_ftp_server:1.25:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xlight_ftp_server:xlight_ftp_server:1.41:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xlight_ftp_server:xlight_ftp_server:1.45:*:*:*:*:*:*:* | ||
| cpe:2.3:a:xlight_ftp_server:xlight_ftp_server:1.52:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



