hfiref0x CVE Vulnerabilities & Metrics

Focus on hfiref0x vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About hfiref0x Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hfiref0x. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hfiref0x CVEs: 3
Earliest CVE date: 17 Nov 2017, 00:29 UTC
Latest CVE date: 01 Dec 2025, 16:15 UTC

Latest CVE reference: CVE-2025-65403

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hfiref0x CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.5

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 0
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS hfiref0x CVEs

These are the five CVEs with the highest CVSS scores for hfiref0x, sorted by severity first and recency.

All CVEs for hfiref0x

CVE-2025-65403 hfiref0x vulnerability CVSS: 0 01 Dec 2025, 16:15 UTC

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-24042 hfiref0x vulnerability CVSS: 0 21 Jan 2023, 02:15 UTC

A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.

CVE-2017-1000218 hfiref0x vulnerability CVSS: 7.5 17 Nov 2017, 00:29 UTC

LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.