oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15622
http://www.time-travellers.org/oftpd/oftpd-dos.html
http://www.securityfocus.com/bid/9980
http://www.debian.org/security/2004/dsa-473