Code Crafters maintains a focused product line centered on mail server and messaging infrastructure, with a narrowly scoped but more prominent than typical vulnerability footprint within that domain. The vendor's observed disclosures affect its Ability Mail Server and Ability Server products and reflect the parsing and protocol-handling demands of mail infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Code Crafters over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1626MEDIUM Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command. | Oct 22, 2004 | 5.0 | 67 | NO | YES |
CVE-2004-1627HIGH Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command. | Oct 22, 2004 | 7.5 | 35 | NO | YES |
CVE-2017-17752MEDIUM Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is | Dec 20, 2017 | 6.1 | 31 | NO | YES |
CVE-2024-0547HIGH A vulnerability has been found in Ability FTP Server 2.34 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component APPE Command Ha | Jan 15, 2024 | 7.5 | 21 | NO | NO |
CVE-2019-9557MEDIUM Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript | Mar 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2013-6162MEDIUM Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email. | Dec 21, 2013 | 4.3 | 21 | NO | YES |
CVE-2004-2494MEDIUM Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter. | Dec 31, 2004 | 4.3 | 21 | NO | YES |
CVE-2004-2495HIGH The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneo | Dec 31, 2004 | 7.8 | 20 | NO | NO |
CVE-2009-3445MEDIUM Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command. | Sep 28, 2009 | 5.0 | 16 | NO | NO |
CVE-2007-6101MEDIUM Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and | Nov 23, 2007 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Code Crafters.
Media articles that mention a CVE ID that affects a product developed by Code Crafters — matched by CVE ID, not by vendor name.