Estrongs develops a popular file-management application for mobile and desktop platforms, with its vulnerability exposure concentrating in ES File Explorer and related file-manager products. The recurring weakness classes center on path-traversal conditions, cleartext transmission of sensitive data, and authentication gaps—characteristic risks in file-access and data-handling utilities—and vulnerabilities in this product line frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Estrongs over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6447HIGH The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on t | Jan 16, 2019 | 8.1 | 81 | NO | YES |
CVE-2019-11380HIGH The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading | Sep 5, 2019 | 7.5 | 26 | NO | NO |
CVE-2015-1876HIGH Directory traversal vulnerability in ES File Explorer 3.2.4.1. | Aug 28, 2017 | 7.5 | 20 | NO | NO |
CVE-2014-1970MEDIUM Directory traversal vulnerability in the ES File Explorer File Manager application before 3.0.4 for Android allows remote attackers to overwrite or create arbitrary files via unspe | Mar 20, 2014 | 5.8 | 19 | NO | NO |
CVE-2012-0322MEDIUM The EStrongs ES File Explorer application 1.6.0.2 through 1.6.1.1 for Android does not properly restrict access, which allows remote attackers to read arbitrary files via vectors i | Mar 5, 2012 | 4.3 | 18 | NO | NO |
CVE-2019-8345MEDIUM The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS | Feb 15, 2019 | 4.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Estrongs.
Media articles that mention a CVE ID that affects a product developed by Estrongs — matched by CVE ID, not by vendor name.