Bigantsoft develops a focused line of enterprise messaging and collaboration server products including Bigant Server, Bigant IM Message Server, and Bigant Messenger, which serve as centralized communication platforms for business environments. The vendor's vulnerabilities recur around application-layer weaknesses including buffer-boundary violations, SQL injection, unrestricted file uploads, authentication bypass, and cross-site request forgery, reflecting the input-handling and access-control demands of web-facing messaging infrastructure; these issues have frequently acquired public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bigantsoft over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1914HIGH Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in | Apr 22, 2008 | 10.0 | 81 | NO | YES |
CVE-2009-4660HIGH Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 66 | Mar 3, 2010 | 10.0 | 76 | NO | YES |
CVE-2012-6275HIGH Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH | Feb 24, 2013 | 10.0 | 74 | NO | YES |
CVE-2012-6274MEDIUM BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via u | Feb 24, 2013 | 5.0 | 61 | NO | YES |
CVE-2022-23347HIGH BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. | Mar 21, 2022 | 7.5 | 36 | NO | YES |
CVE-2025-0364CRITICAL BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker ca | Feb 4, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-23346HIGH BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues. | Mar 21, 2022 | 8.8 | 31 | NO | NO |
CVE-2024-54761MEDIUM BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. | Jan 9, 2025 | 6.3 | 28 | NO | YES |
CVE-2022-23352HIGH An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS). | Mar 21, 2022 | 7.5 | 28 | NO | NO |
CVE-2021-43430HIGH An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files. | Apr 7, 2022 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bigantsoft.
Media articles that mention a CVE ID that affects a product developed by Bigantsoft — matched by CVE ID, not by vendor name.