← Back to CVE List
Vulnerability Intelligence Report
FileZilla 3.40.0 Denial of Service via Local Search

CVE-2019-25683

FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.

No Active Exploit Signals
CVSS Base Score
6.9
MEDIUM
EPSS Probability:0.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-532 ↗Insertion of Sensitive Information into Log File

Affected Products & Versions

Vendor Product Affected Versions
Filezilla-Project FileZilla 3.40.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.173%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-04-05T15:16:49
Published2026-04-05T20:45:32
Patch Date2019-02-20
Last Updated2026-04-06T18:12:56

LINK COPIED TO CLIPBOARD