Ws Ftp

Vendor:

First CVE: Apr 24, 2007 · Active for 19 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ws Ftp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Nov 3, 2017
3,185 days ago

CVE Severity & Scoring

Ws Ftp8 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local1 (12.5%)
Network0 (0.0%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None1 (12.5%)
Unknown7 (87.5%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (87.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.
Nov 3, 20177.835NOYES
The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string
Jul 17, 20077.831NONO
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status c
Apr 21, 20104.326NOYES
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogSe
Dec 19, 20085.025NOYES
Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereferen
Apr 24, 20077.821NONO
The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of l
Feb 6, 20085.018NONO
Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a r
Dec 19, 20085.016NONO
Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly h
Aug 28, 20074.314NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
37.5% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Ws Ftp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.5.29.017.825.2%00
6.115.05.6%00
6.025.05.3%01
5.0525.05.3%01
5.0425.05.3%01
5.0325.05.3%01
5.0225.05.3%01
5.0125.05.3%01
5.0025.05.3%01
4.0225.05.3%01
4.0125.05.3%01
4.0025.05.3%01
3.1425.05.3%01
3.1.325.05.3%01
3.1.225.05.3%01
3.1.125.05.3%01
3.1.025.05.3%01
3.0.125.05.3%01
3.025.05.3%01
2.0325.05.3%01