FileZilla Server versions prior to 0.9.6 are vulnerable to denial of service when processing filenames containing MS-DOS device names such as CON, NUL, COM1, LPT1, and others. Remote attackers can cause the server to crash or become unresponsive by requesting files with these reserved device names.
id: CVE-2005-0850
info:
name: FileZilla Server < 0.9.6 - DoS via MS-DOS Device Names
author: pu
...