FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process.
Metrics
Affected Vendors & Products
References
History
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process. | |
| Title | FTP Voyager 16.2.0 Denial of Service via Malformed Site Profile | |
| First Time appeared |
Solarwinds
Solarwinds ftp Voyager |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:solarwinds:ftp_voyager:16.2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Solarwinds
Solarwinds ftp Voyager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-04T16:14:00.501Z
Reserved: 2026-04-04T13:28:29.879Z
Link: CVE-2018-25252
No data.
Status : Received
Published: 2026-04-04T14:16:21.367
Modified: 2026-04-04T14:16:21.367
Link: CVE-2018-25252
No data.
OpenCVE Enrichment
No data.