echatserver records
7 published records for vendor echatserver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 14.3%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-427 Uncontrolled Search Path Element1
- CWE-522 Insufficiently Protected Credentials1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-940 Improper Verification of Source of a Communication Channel1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2017-9544Weaponized | There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1.echatserver · easy chat server · CWE-787 | Critical9.8 | — | 24.1% | Jun 12, 2017 |
37Monitor | CVE-2018-25221No exploit | EChat Server 3.1 Buffer Overflow via chat.ghp username Parameterechatserver · easy chat server · CWE-787 | Critical9.3 | — | 0.8% | Mar 28, 2026 |
34Monitor | CVE-2019-25613No exploit | Easy Chat Server 3.1 Denial of Service via message Parameterechatserver · easy chat server · CWE-940 | High8.7 | — | 0.5% | Mar 22, 2026 |
31Monitor | CVE-2017-9557No exploit | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username paraechatserver · easy chat server · CWE-522 | High7.5 | — | 1.7% | Jun 12, 2017 |
31Monitor | CVE-2022-44939No exploit | Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll.echatserver · easy chat server · CWE-427 | High7.8 | — | 0.4% | Jan 6, 2023 |
30Monitor | CVE-2017-9543No exploit | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST reechatserver · easy chat server · CWE-640 | High7.5 | — | 1.3% | Jun 12, 2017 |
30Monitor | CVE-2019-20502No exploit | An issue was discovered in EFS Easy Chat Server 3.1.echatserver · easy chat server · CWE-120 | High7.5 | — | 1.1% | Mar 5, 2020 |
- CVE-2017-954446Plan
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1.
CriticalCVSS 9.8WeaponizedEPSS 24%echatserver · easy chat serverJun 12, 2017
- CVE-2018-2522137Monitor
EChat Server 3.1 Buffer Overflow via chat.ghp username Parameter
CriticalCVSS 9.3No exploitEPSS 1%echatserver · easy chat serverMar 28, 2026
- CVE-2019-2561334Monitor
Easy Chat Server 3.1 Denial of Service via message Parameter
HighCVSS 8.7No exploitEPSS 1%echatserver · easy chat serverMar 22, 2026
- CVE-2017-955731Monitor
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username para
HighCVSS 7.5No exploitEPSS 2%echatserver · easy chat serverJun 12, 2017
- CVE-2022-4493931Monitor
Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll.
HighCVSS 7.8No exploitEPSS 0%echatserver · easy chat serverJan 6, 2023
- CVE-2017-954330Monitor
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST re
HighCVSS 7.5No exploitEPSS 1%echatserver · easy chat serverJun 12, 2017
- CVE-2019-2050230Monitor
An issue was discovered in EFS Easy Chat Server 3.1.
HighCVSS 7.5No exploitEPSS 1%echatserver · easy chat serverMar 5, 2020