Texas Imperial Software's vulnerability profile centers on a narrow product line of FTP server software, notably WFTPD and its commercial variants (WFTPD Pro, WFTPD Pro Explorer, WFTPD Pro Server), which have been widely deployed in enterprise file-transfer infrastructure. Although the vendor's overall CVE volume is modest relative to broad-platform vendors, the disclosure footprint is prominent enough to warrant sustained attention, and public exploit code frequently becomes available for vulnerabilities in this product category. The recurring weakness classes span memory-safety issues including buffer-boundary violations and out-of-bounds access, alongside sensitive information exposure, reflecting the protocol-parsing and authentication demands of FTP server implementations. Defenders relying on WFTPD or its variants should prioritize patch deployment and consider restricting FTP access to internal networks or modern alternatives; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Texas Imperial Software over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4318MEDIUM Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands. | Aug 24, 2006 | 6.5 | 68 | NO | YES |
CVE-1999-0950HIGH Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Oct 28, 1999 | 10.0 | 38 | NO | YES |
CVE-2001-0296HIGH Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command. | May 3, 2001 | 10.0 | 36 | NO | YES |
CVE-2006-5826MEDIUM Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) vi | Nov 10, 2006 | 5.8 | 28 | NO | YES |
CVE-2004-2367MEDIUM The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command. | Dec 31, 2004 | 5.0 | 28 | NO | YES |
CVE-2004-0340HIGH Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via l | Nov 23, 2004 | 7.2 | 27 | NO | YES |
CVE-2000-0645MEDIUM WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that do | Jul 21, 2000 | 6.4 | 27 | NO | YES |
CVE-2007-6473MEDIUM Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command. | Dec 20, 2007 | 5.8 | 25 | NO | YES |
CVE-2001-1386HIGH WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension. | Jul 1, 2001 | 7.5 | 25 | NO | NO |
CVE-2000-0644MEDIUM WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing. | Jul 21, 2000 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Texas Imperial Software.
Media articles that mention a CVE ID that affects a product developed by Texas Imperial Software — matched by CVE ID, not by vendor name.