Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ipswitch

First CVE: Jan 2, 1999Active for: 28 yearsTotal CVEs: 109
44.1
VTI Score
High

Ipswitch develops a focused portfolio of file-transfer, email, and collaboration server products that sit in critical administrative and messaging workflows, despite its narrow product range representing a prominent position in the vulnerability landscape. Vulnerabilities affecting the vendor span a meaningful share reaching serious severity, frequently acquire public exploit tooling, and recur through weakness classes including buffer overflows, cross-site scripting, path traversal, and information disclosure that are characteristic of network-facing server applications. The exposure concentrates in flagship products such as WS_FTP Server, iMail, and the Ipswitch Collaboration Suite, reflecting the parsing, authentication, and file-handling demands of enterprise transfer and messaging infrastructure. Defenders should treat updates to these products as high-priority for systems accepting external connections or handling sensitive file operations; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
109
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ipswitch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 1999
27 years ago
Most Recent CVE
Oct 31, 2019
2,458 days ago

Products(26 total)

Top CVEs

Signals from CVEs in this vendor scope (109 CVEs).

109 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0297HIGH
Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service
Nov 23, 200410.083NOYES
CVE-2006-4847MEDIUM
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 comman
Sep 19, 20066.579NOYES
CVE-2007-3925MEDIUM
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Sear
Jul 21, 20076.578NOYES
CVE-2004-1520MEDIUM
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.
Dec 31, 20044.676NOYES
CVE-2011-4722HIGH
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of a
Dec 28, 20147.874NOYES
CVE-2003-0772HIGH
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT
Sep 22, 20037.574NOYES
CVE-2006-4379HIGH
Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to ex
Sep 8, 20067.569NOYES
CVE-1999-1551MEDIUM
Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.
Mar 2, 19995.061NOYES
CVE-2005-1255HIGH
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow re
May 25, 200510.059NOYES
CVE-2004-1135MEDIUM
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR co
Jan 10, 20055.057NOYES
View all 109 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products109 CVEs
54%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.9%)
Network17 (15.6%)
Unknown91 (83.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (16.5%)
High0 (0.0%)
Unknown91 (83.5%)
User Interaction
None14 (12.8%)
Unknown91 (83.5%)
Required4 (3.7%)
Privileges Required
Low4 (3.7%)
High0 (0.0%)
None14 (12.8%)
Unknown91 (83.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (109 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
5.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
37 CVEs
33.9% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ipswitch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ipswitch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ipswitch's Products

View all 1 CNAs →

Top CWEs