Efs Software maintains a small portfolio of legacy server and communication applications including web servers, FTP servers, and groupware products, many of which have long been out of active development. While the vendor's disclosure volume is modest, vulnerabilities affecting these products frequently acquire public exploit code, reflecting their accessibility and continued presence in older network deployments. The recurring weakness classes center on memory-buffer handling issues and related low-level flaws that are characteristic of native-code server software from earlier development eras. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Efs Software over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3952HIGH Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command. NOTE: the p | Aug 1, 2006 | 7.5 | 75 | NO | YES |
CVE-2004-2466MEDIUM chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was | Dec 31, 2004 | 5.0 | 75 | NO | YES |
CVE-2006-1159HIGH Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via fo | Mar 12, 2006 | 7.8 | 31 | NO | YES |
CVE-2023-4494CRITICAL Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name v | Oct 4, 2023 | 9.8 | 28 | NO | NO |
CVE-2006-1161MEDIUM Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Window | Mar 12, 2006 | 6.5 | 26 | NO | YES |
CVE-2006-5714MEDIUM Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of | Nov 4, 2006 | 5.0 | 24 | NO | YES |
CVE-2006-5715MEDIUM Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end | Nov 4, 2006 | 5.0 | 24 | NO | YES |
CVE-2006-4654MEDIUM Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string sp | Sep 9, 2006 | 5.1 | 23 | NO | YES |
CVE-2004-1744MEDIUM Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests. | Aug 24, 2004 | 5.0 | 23 | NO | YES |
CVE-2023-4497MEDIUM Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registres | Oct 4, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Efs Software.
Media articles that mention a CVE ID that affects a product developed by Efs Software — matched by CVE ID, not by vendor name.