Skip to main content

CVE-2010-20049

CVSS Score Not Available
54.24%
MEDIUM RiskEPSS (98th percentile)

LeapFTP < 3.1.x contains a stack-based buffer overflow vulnerability in its FTP client parser. When the client receives a directory listing containing a filename longer than 528 bytes, the application fails to properly bound-check the input and overwrites the Structured Exception Handler (SEH) chain. This allows an attacker operating a malicious FTP server to execute arbitrary code on the victim’s machine when the file is listed or downloaded.

Published: 8/20/2025
Modified: 8/22/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

54.24%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 54.24% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.