CVE-2018-18861
9.8
CRITICAL · CVSS 3.0 · EPSS 4.5% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.46% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-20 |
| Last modified | 2026-08-19 |
Affected (1)
| Vendor | Product |
|---|---|
| pcman | ftp server |
References
→ the Explorer · watch your stack · NVD