CVE-2010-20049
CVSS Score Not Available
54.24%
MEDIUM RiskEPSS (98th percentile)
LeapFTP < 3.1.x contains a stack-based buffer overflow vulnerability in its FTP client parser. When the client receives a directory listing containing a filename longer than 528 bytes, the application fails to properly bound-check the input and overwrites the Structured Exception Handler (SEH) chain. This allows an attacker operating a malicious FTP server to execute arbitrary code on the victim’s machine when the file is listed or downloaded.
Published: 8/20/2025
Modified: 8/22/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
54.24%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 54.24% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.