Bolintech offers an FTP server product that has attracted vulnerability disclosures, with the exposure concentrated in Dream FTP Server. The observed weakness classifications have been marked with placeholder categorization in NVD records; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bolintech over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2074MEDIUM Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands. | Dec 31, 2004 | 5.0 | 55 | NO | YES |
CVE-2004-0277HIGH Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the u | Nov 23, 2004 | 10.0 | 48 | NO | YES |
CVE-2007-0338HIGH Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers | Jan 18, 2007 | 7.5 | 30 | NO | YES |
CVE-2006-6724MEDIUM BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of service (application crash) via a certain invalid PORT command. | Dec 26, 2006 | 4.0 | 21 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bolintech.
Media articles that mention a CVE ID that affects a product developed by Bolintech — matched by CVE ID, not by vendor name.