Altools develops a focused line of file-transfer and utility software including an FTP server, password management, and music applications, with a modest but concentrated vulnerability footprint. The recurring weakness classes center on input-handling and memory-safety issues such as cross-site scripting, buffer bounds violations, and format-string flaws that are typical of application-layer software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altools over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7809MEDIUM ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by improper validation of user input. A remote attacker could | May 15, 2020 | 6.1 | 21 | NO | NO |
CVE-2007-4549MEDIUM Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrary code via an ALPass DB (APW) file containing (1) a long fil | Aug 28, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-4550MEDIUM Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an fnm field | Aug 28, 2007 | 5.1 | 16 | NO | NO |
CVE-2006-5949MEDIUM Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequ | Nov 17, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-5950MEDIUM Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors relate | Nov 17, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altools.
Media articles that mention a CVE ID that affects a product developed by Altools — matched by CVE ID, not by vendor name.