Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Estsoft

First CVE: Oct 14, 2005Active for: 21 yearsTotal CVEs: 19
37.0
VTI Score
Medium

Estsoft maintains a portfolio of file compression, antivirus, FTP, and system-utility applications with a modest but prominent vulnerability footprint centered on memory-safety and bounds-checking weaknesses. Its vulnerabilities frequently acquire public exploit code, reflecting the direct network and file-handling exposure of tools such as ALZip, ALyac, ALFtp, ALSee, and ALTools; the recurring weakness classes including buffer overflows, integer overflows, and out-of-bounds writes are characteristic of native-code implementations handling untrusted file formats and network streams. Live severity, exploitation, and coverage metrics are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Estsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2005
20 years ago
Most Recent CVE
Dec 3, 2025
233 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-2702HIGH
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot)
Jun 13, 20089.341NOYES
CVE-2011-1336HIGH
Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.
Jul 7, 20119.330NONO
CVE-2012-0315HIGH
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an ext
Feb 22, 20129.328NONO
CVE-2006-2899MEDIUM
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple
Jun 7, 20066.527NOYES
CVE-2022-32543HIGH
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in ar
Aug 5, 20227.825NONO
CVE-2022-29886HIGH
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in a
Aug 5, 20227.825NONO
CVE-2018-5196HIGH
Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker co
Dec 21, 20187.825NONO
CVE-2017-11323HIGH
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as
Aug 19, 20177.825NONO
CVE-2019-12810HIGH
A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resul
Aug 30, 20197.824NONO
CVE-2019-12807HIGH
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By p
Aug 13, 20197.824NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
42%
58%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (57.9%)
Network1 (5.3%)
Unknown7 (36.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (63.2%)
High0 (0.0%)
Unknown7 (36.8%)
User Interaction
None2 (10.5%)
Unknown7 (36.8%)
Required9 (47.4%)
Privileges Required
Low2 (10.5%)
High0 (0.0%)
None10 (52.6%)
Unknown7 (36.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
10.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Estsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Estsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Estsoft's Products

View all 4 CNAs →

Top CWEs