Dxmsoft maintains a narrowly focused file-transfer product line centered on XM Easy Personal FTP Server, a consumer-grade application that despite limited product breadth has achieved notable prominence in the vulnerability landscape. The vendor's disclosures frequently acquire public exploit tooling, reflecting the accessibility of its products and the parsing-oriented weakness classes that recur in its codebase, particularly format-string handling issues. Defenders should treat this vendor's advisories as requiring prompt attention for any exposed instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dxmsoft over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5626MEDIUM XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demonstrated by a -1 argument. | Dec 17, 2008 | 4.0 | 46 | NO | YES |
CVE-2007-1195HIGH Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-222 | Mar 2, 2007 | 7.5 | 30 | NO | YES |
CVE-2006-2225HIGH Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username. | May 5, 2006 | 7.5 | 30 | NO | YES |
CVE-2009-3643MEDIUM Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST commands, a differnt issue than CVE- | Oct 9, 2009 | 5.0 | 26 | NO | YES |
CVE-2006-6750MEDIUM Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a long POR | Dec 27, 2006 | 5.0 | 23 | NO | YES |
CVE-2006-6751MEDIUM Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER c | Dec 27, 2006 | 5.0 | 23 | NO | YES |
CVE-2006-2226MEDIUM Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of service via a long argument to the PORT command. | May 5, 2006 | 5.0 | 23 | NO | YES |
CVE-2009-4048MEDIUM Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DEL | Nov 23, 2009 | 4.0 | 21 | NO | YES |
CVE-2006-5728MEDIUM XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al fla | Nov 6, 2006 | 4.0 | 21 | NO | YES |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dxmsoft.
Media articles that mention a CVE ID that affects a product developed by Dxmsoft — matched by CVE ID, not by vendor name.