Rhinosoft maintains a focused portfolio of file-transfer, DNS, and server-infrastructure products including FTP Voyager, Serv-U, and DNS4Me that serve connectivity and data-exchange roles in networked environments. The vulnerability profile concentrates on path-traversal and memory-buffer boundary issues that recur across these products, and public exploit code is frequently associated with the vendor's disclosures. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rhinosoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4873HIGH Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary | May 26, 2010 | 10.0 | 49 | NO | YES |
CVE-2007-1079HIGH Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command | Feb 22, 2007 | 7.8 | 31 | NO | YES |
CVE-2010-4154HIGH Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backs | Nov 3, 2010 | 9.3 | 27 | NO | NO |
CVE-2004-1691MEDIUM The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data. | Sep 18, 2004 | 5.0 | 23 | NO | YES |
CVE-2004-1939MEDIUM Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter | Apr 14, 2004 | 4.3 | 21 | NO | YES |
CVE-2001-1103HIGH FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbit | Mar 3, 2001 | 7.5 | 20 | NO | NO |
CVE-2004-1690MEDIUM Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL. | Sep 18, 2004 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rhinosoft.
Media articles that mention a CVE ID that affects a product developed by Rhinosoft — matched by CVE ID, not by vendor name.