CERT/CC Vulnerability Note VU#2558 File Transfer Protocol allows data connection hijacking via PASV mode race condition http://www.kb.cert.org/vuls/id/2558
CERT/CC Vulnerability Note VU#258721 : Various FTP clients fail to account for pipe (|) characters in default file names http://www.kb.cert.org/vuls/id/258721