Aclogic maintains a narrow product portfolio centered on CesarFTP, a file-transfer application where vulnerabilities tend toward public exploit availability. The recurring weakness classifications reflect the parsing and protocol complexity inherent to FTP implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aclogic over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2961HIGH Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MK | Jun 12, 2006 | 7.5 | 72 | NO | YES |
CVE-2004-0298MEDIUM CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter. | Nov 23, 2004 | 5.0 | 28 | NO | YES |
CVE-2001-1335MEDIUM Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contain | May 27, 2001 | 5.0 | 25 | NO | YES |
CVE-2001-0826HIGH Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, | Dec 6, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1336HIGH CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges. | May 28, 2001 | 7.5 | 19 | NO | NO |
CVE-2003-0329MEDIUM CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges. | Jun 9, 2003 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aclogic.
Media articles that mention a CVE ID that affects a product developed by Aclogic — matched by CVE ID, not by vendor name.