Fastream develops a focused line of file-transfer and web-serving products, including FTP and HTTP server implementations that occupy a modest but established niche in the infrastructure landscape. The recurring vulnerability signal centers on web-application input-handling issues, particularly cross-site scripting, and the vendor's disclosures have an elevated tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastream over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0676HIGH Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (dou | Aug 6, 2004 | 10.0 | 36 | NO | YES |
CVE-2004-2534HIGH Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perfo | Dec 31, 2004 | 7.8 | 30 | NO | YES |
CVE-2001-0255MEDIUM FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname. | Jun 2, 2001 | 5.0 | 25 | NO | YES |
CVE-2003-1151MEDIUM Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "4 | Oct 28, 2003 | 4.3 | 21 | NO | YES |
CVE-2001-0256HIGH FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username. | Jun 2, 2001 | 7.5 | 20 | NO | NO |
CVE-2000-0831HIGH Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username. | Nov 14, 2000 | 7.5 | 20 | NO | NO |
CVE-2005-1646HIGH The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in | May 18, 2005 | 7.5 | 19 | NO | NO |
CVE-2004-0677MEDIUM Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due t | Aug 6, 2004 | 5.0 | 15 | NO | NO |
CVE-2004-1941MEDIUM Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist. | Apr 19, 2004 | 5.0 | 15 | NO | NO |
CVE-2001-0254MEDIUM FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command. | Jun 2, 2001 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastream.
Media articles that mention a CVE ID that affects a product developed by Fastream — matched by CVE ID, not by vendor name.