Estsoft maintains a portfolio of file compression, antivirus, FTP, and system-utility applications with a modest but prominent vulnerability footprint centered on memory-safety and bounds-checking weaknesses. Its vulnerabilities frequently acquire public exploit code, reflecting the direct network and file-handling exposure of tools such as ALZip, ALyac, ALFtp, ALSee, and ALTools; the recurring weakness classes including buffer overflows, integer overflows, and out-of-bounds writes are characteristic of native-code implementations handling untrusted file formats and network streams. Live severity, exploitation, and coverage metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Estsoft over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2702HIGH Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) | Jun 13, 2008 | 9.3 | 41 | NO | YES |
CVE-2011-1336HIGH Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file. | Jul 7, 2011 | 9.3 | 30 | NO | NO |
CVE-2012-0315HIGH Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an ext | Feb 22, 2012 | 9.3 | 28 | NO | NO |
CVE-2006-2899MEDIUM Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple | Jun 7, 2006 | 6.5 | 27 | NO | YES |
CVE-2022-32543HIGH An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in ar | Aug 5, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-29886HIGH An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in a | Aug 5, 2022 | 7.8 | 25 | NO | NO |
CVE-2018-5196HIGH Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker co | Dec 21, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-11323HIGH Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as | Aug 19, 2017 | 7.8 | 25 | NO | NO |
CVE-2019-12810HIGH A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resul | Aug 30, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-12807HIGH Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By p | Aug 13, 2019 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Estsoft.
Media articles that mention a CVE ID that affects a product developed by Estsoft — matched by CVE ID, not by vendor name.