CVE-2001-0136
CVE-2001-0136 is a medium-severity vulnerability in Proftpd with a CVSS 2.0 base score of 5.0. Its EPSS exploit-prediction score of 45% places it in the 99th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-401.
Key facts
- Severity: Medium (CVSS 2.0 base score 5.0)
- EPSS exploit prediction: 45% (99th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-401
- Affected product: Proftpd
- Published:
- Last modified:
Description
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.
Frequently asked questions
- What is CVE-2001-0136?
- Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.
- How severe is CVE-2001-0136?
- CVE-2001-0136 has a CVSS 2.0 base score of 5.0, rated medium severity.
- Is CVE-2001-0136 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 45% (99th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2001-0136?
- CVE-2001-0136 primarily affects Proftpd. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2001-0136?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2001-0136 published?
- CVE-2001-0136 was published on 2001-03-12 and last updated on 2026-06-16.
References
- http://archives.neohapsis.com/archives/bugtraq/2001-01/0122.html
- http://archives.neohapsis.com/archives/bugtraq/2001-01/0132.html
- http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000380
- http://www.debian.org/security/2001/dsa-029
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3
- http://www.securityfocus.com/archive/1/152206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5801
Affected products (4)
- cpe:2.3:a:proftpd:proftpd:1.2.0:rc2:*:*:*:*:*:*
- cpe:2.3:o:conectiva:linux:*:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:2.2:*:*:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*
More vulnerabilities in Proftpd
- CVE-2015-3306 — Critical (CVSS 10.0): The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and…
- CVE-2010-4221 — Critical (CVSS 10.0): Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow…
- CVE-2010-20103 — Critical (CVSS 9.8): A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and…
- CVE-2019-12815 — Critical (CVSS 9.8): An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and…
- CVE-2011-4130 — Critical (CVSS 9.0): Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute…
- CVE-2026-63090 — High (CVSS 8.8): ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that…
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →