Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codecrafters

First CVE: Dec 20, 2017Active for: 9 yearsTotal CVEs: 10

Codecrafters maintains a focused line of server and mail-handling products (Ability Mail Server, Ability Server, Ability FTP Server) with a durable signal centered on application-layer input-handling and resource-management issues, particularly cross-site scripting and improper resource release. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 72% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Codecrafters over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2004
21 years ago
Most Recent CVE
Jan 15, 2024
921 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1626MEDIUM
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.
Oct 22, 20045.067NOYES
CVE-2004-1627HIGH
Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.
Oct 22, 20047.535NOYES
CVE-2017-17752MEDIUM
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is
Dec 20, 20176.131NOYES
CVE-2024-0547HIGH
A vulnerability has been found in Ability FTP Server 2.34 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component APPE Command Ha
Jan 15, 20247.521NONO
CVE-2019-9557MEDIUM
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript
Mar 12, 20196.121NONO
CVE-2013-6162MEDIUM
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.
Dec 21, 20134.321NOYES
CVE-2004-2494MEDIUM
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.
Dec 31, 20044.321NOYES
CVE-2004-2495HIGH
The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneo
Dec 31, 20047.820NONO
CVE-2009-3445MEDIUM
Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command.
Sep 28, 20095.016NONO
CVE-2007-6101MEDIUM
Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and
Nov 23, 20074.014NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
70%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (30.0%)
Unknown7 (70.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (30.0%)
High0 (0.0%)
Unknown7 (70.0%)
User Interaction
None1 (10.0%)
Unknown7 (70.0%)
Required2 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (30.0%)
Unknown7 (70.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
10.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
50.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codecrafters.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codecrafters — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codecrafters's Products

View all 2 CNAs →

Top CWEs