Typsoft develops FTP server and file-transfer software that operates in network infrastructure roles where input parsing and memory management are critical. The vendor's disclosures recur around improper input validation and buffer-boundary issues, and vulnerabilities in this product line frequently acquire public exploit code. Current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typsoft over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-1035HIGH Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD c | Dec 11, 2000 | 10.0 | 41 | NO | YES |
CVE-2005-3294MEDIUM Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR commands. NOTE: it was later r | Oct 23, 2005 | 5.0 | 31 | NO | YES |
CVE-2012-5329MEDIUM Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command. | Oct 8, 2012 | 4.0 | 26 | NO | YES |
CVE-2001-1156MEDIUM TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR. | Oct 8, 2001 | 5.0 | 25 | NO | YES |
CVE-2009-1668MEDIUM TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer. | May 18, 2009 | 4.0 | 24 | NO | YES |
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, ( | Dec 31, 2004 | 2.1 | 22 | NO | YES |
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command w | Nov 29, 2009 | 3.5 | 20 | NO | YES |
CVE-2004-0252MEDIUM TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name. | Nov 23, 2004 | 5.0 | 19 | NO | NO |
CVE-2002-1354MEDIUM Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command. | Dec 18, 2002 | 5.0 | 19 | NO | NO |
CVE-2002-0558MEDIUM Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST | Jul 3, 2002 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typsoft.
Media articles that mention a CVE ID that affects a product developed by Typsoft — matched by CVE ID, not by vendor name.