FlashFXP is a focused file-transfer client that has surfaced vulnerabilities centered on memory-safety issues, including buffer-boundary conditions and unclassified platform-specific weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flashfxp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4992HIGH Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox. | Sep 19, 2012 | 9.0 | 45 | NO | YES |
CVE-2007-0825HIGH FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested direct | Feb 7, 2007 | 7.8 | 30 | NO | YES |
CVE-2003-1483MEDIUM FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access. | Dec 31, 2003 | 6.4 | 21 | NO | NO |
FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties. | Dec 31, 2002 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flashfxp.
Media articles that mention a CVE ID that affects a product developed by Flashfxp — matched by CVE ID, not by vendor name.