Ipswitch develops a focused portfolio of file-transfer, email, and collaboration server products that sit in critical administrative and messaging workflows, despite its narrow product range representing a prominent position in the vulnerability landscape. Vulnerabilities affecting the vendor span a meaningful share reaching serious severity, frequently acquire public exploit tooling, and recur through weakness classes including buffer overflows, cross-site scripting, path traversal, and information disclosure that are characteristic of network-facing server applications. The exposure concentrates in flagship products such as WS_FTP Server, iMail, and the Ipswitch Collaboration Suite, reflecting the parsing, authentication, and file-handling demands of enterprise transfer and messaging infrastructure. Defenders should treat updates to these products as high-priority for systems accepting external connections or handling sensitive file operations; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipswitch over time
Signals from CVEs in this vendor scope (109 CVEs).
109 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0297HIGH Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service | Nov 23, 2004 | 10.0 | 83 | NO | YES |
CVE-2006-4847MEDIUM Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 comman | Sep 19, 2006 | 6.5 | 79 | NO | YES |
CVE-2007-3925MEDIUM Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Sear | Jul 21, 2007 | 6.5 | 78 | NO | YES |
CVE-2004-1520MEDIUM Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. | Dec 31, 2004 | 4.6 | 76 | NO | YES |
CVE-2011-4722HIGH Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of a | Dec 28, 2014 | 7.8 | 74 | NO | YES |
CVE-2003-0772HIGH Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT | Sep 22, 2003 | 7.5 | 74 | NO | YES |
CVE-2006-4379HIGH Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to ex | Sep 8, 2006 | 7.5 | 69 | NO | YES |
CVE-1999-1551MEDIUM Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL. | Mar 2, 1999 | 5.0 | 61 | NO | YES |
CVE-2005-1255HIGH Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow re | May 25, 2005 | 10.0 | 59 | NO | YES |
CVE-2004-1135MEDIUM Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR co | Jan 10, 2005 | 5.0 | 57 | NO | YES |
Signals from CVEs in this vendor scope (109 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipswitch.
Media articles that mention a CVE ID that affects a product developed by Ipswitch — matched by CVE ID, not by vendor name.