CVE-2006-6184
HIGH 10.0EPSS 65.9%
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 65.87% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2006-12-01
- Updated
- 2024-08-07
Proof-of-concept exploits (4)
- http://www.exploit-db.com/exploits/24952
- http://www.exploit-db.com/exploits/16350
- b03902043/CVE-2006-61840★ · 2019-09-01
- shauntdergrigorian/cve-2006-618411★ · 2020-11-03
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/24952
- https://www.exploit-db.com/exploits/16350
- https://www.exploit-db.com/exploits/2887
- https://www.exploit-db.com/exploits/10603