PatchSiren

Serv-U CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Serv-U CVE published 2026-04-04

CVE-2018-25252

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability can be triggered by creating a malicious site profile containing 500 bytes of repeated characters and pasting it into the IP field, which c [truncated]