Youngzsoft maintains a focused line of messaging and proxy infrastructure products, notably CMailServer and CCProxy, that serve niche deployment contexts and have attracted public exploit tooling. The recurring vulnerability signal centers on memory-buffer handling issues alongside cases classified under broader categories, reflecting typical firmware and systems-software concerns. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Youngzsoft over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2416HIGH Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request. | Dec 31, 2004 | 7.5 | 70 | NO | YES |
CVE-2003-0280HIGH Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands. | Jun 16, 2003 | 10.0 | 42 | NO | YES |
CVE-2008-6922HIGH Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary code via a long argument to the (1) CreateUserPath, (2) Logou | Aug 10, 2009 | 9.3 | 37 | NO | YES |
CVE-2002-0799HIGH Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. | Aug 12, 2002 | 7.5 | 35 | NO | YES |
CVE-2004-2685HIGH Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a diff | Dec 31, 2004 | 7.5 | 33 | NO | YES |
CVE-2004-1128HIGH Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachment with a long filename. | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2008-6415HIGH Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname. | Mar 6, 2009 | 10.0 | 26 | NO | NO |
CVE-2004-1129HIGH SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary S | Jan 10, 2005 | 10.0 | 25 | NO | NO |
CVE-2004-1130MEDIUM Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary web script or HTML via personal information fields, such as (1 | Jan 10, 2005 | 6.8 | 18 | NO | NO |
CVE-2007-1991MEDIUM Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via t | Apr 12, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Youngzsoft.
Media articles that mention a CVE ID that affects a product developed by Youngzsoft — matched by CVE ID, not by vendor name.