Ws Ftp
Vendor:
First CVE: Apr 24, 2007 · Active for 19 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ws Ftp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Nov 3, 2017
3,185 days ago
CVE Severity & Scoring
Ws Ftp8 CVEs
63%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network0 (0.0%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None1 (12.5%)
Unknown7 (87.5%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (87.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16513HIGH Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729. | Nov 3, 2017 | 7.8 | 35 | NO | YES |
CVE-2007-3823HIGH The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string | Jul 17, 2007 | 7.8 | 31 | NO | NO |
CVE-2009-4775MEDIUM Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status c | Apr 21, 2010 | 4.3 | 26 | NO | YES |
CVE-2008-5692MEDIUM Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogSe | Dec 19, 2008 | 5.0 | 25 | NO | YES |
CVE-2007-2213HIGH Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereferen | Apr 24, 2007 | 7.8 | 21 | NO | NO |
CVE-2008-0608MEDIUM The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of l | Feb 6, 2008 | 5.0 | 18 | NO | NO |
CVE-2008-5693MEDIUM Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a r | Dec 19, 2008 | 5.0 | 16 | NO | NO |
CVE-2007-4555MEDIUM Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly h | Aug 28, 2007 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
37.5% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Ws Ftp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.5.29.0 | 1 | 7.8 | 25.2% | 0 | 0 |
| 6.1 | 1 | 5.0 | 5.6% | 0 | 0 |
| 6.0 | 2 | 5.0 | 5.3% | 0 | 1 |
| 5.05 | 2 | 5.0 | 5.3% | 0 | 1 |
| 5.04 | 2 | 5.0 | 5.3% | 0 | 1 |
| 5.03 | 2 | 5.0 | 5.3% | 0 | 1 |
| 5.02 | 2 | 5.0 | 5.3% | 0 | 1 |
| 5.01 | 2 | 5.0 | 5.3% | 0 | 1 |
| 5.00 | 2 | 5.0 | 5.3% | 0 | 1 |
| 4.02 | 2 | 5.0 | 5.3% | 0 | 1 |
| 4.01 | 2 | 5.0 | 5.3% | 0 | 1 |
| 4.00 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.14 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.1.3 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.1.2 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.1.1 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.1.0 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.0.1 | 2 | 5.0 | 5.3% | 0 | 1 |
| 3.0 | 2 | 5.0 | 5.3% | 0 | 1 |
| 2.03 | 2 | 5.0 | 5.3% | 0 | 1 |