ESTsoft records
17 published records for vendor estsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-787 Out-of-bounds Write2
- CWE-823 Use of Out-of-range Pointer Offset2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-680 Integer Overflow to Buffer Overflow2
- CWE-426 Untrusted Search Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2008-2702Proof of concept | Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwestsoft · alftp · CWE-22 | Critical9.3 | — | 10.7% | Jun 13, 2008 |
39Monitor | CVE-2011-1336No exploit | Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.estsoft · alzip · CWE-119 | Critical9.3 | — | 5.5% | Jul 7, 2011 |
38Monitor | CVE-2012-0315No exploit | Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a direcestsoft · alftp | Critical9.3 | — | 2.2% | Feb 22, 2012 |
32Monitor | CVE-2017-11323No exploit | Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device estsoft · alzip · CWE-119 | High7.8 | — | 3.0% | Aug 19, 2017 |
31Monitor | CVE-2019-12807No exploit | Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing estsoft · alzip · CWE-119 | High7.8 | — | 1.6% | Aug 13, 2019 |
31Monitor | CVE-2018-5196No exploit | Alzip Stack Overflow Vulnerabilityestsoft · alzip · CWE-787 | High7.8 | — | 1.4% | Dec 21, 2018 |
31Monitor | CVE-2019-12810No exploit | A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39.estsoft · alsee · CWE-787 | High7.8 | — | 1.2% | Aug 30, 2019 |
31Monitor | CVE-2022-32543No exploit | An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.estsoft · alyac · CWE-680 | High7.8 | — | 0.5% | Aug 5, 2022 |
31Monitor | CVE-2022-29886No exploit | An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.estsoft · alyac · CWE-680 | High7.8 | — | 0.5% | Aug 5, 2022 |
31Monitor | CVE-2018-10027No exploit | ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific destsoft · alzip · CWE-426 | High7.8 | — | 0.4% | May 17, 2018 |
31Monitor | CVE-2019-12808No exploit | ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission.estsoft · altools · CWE-264 | High7.8 | — | 0.4% | Aug 13, 2019 |
27Monitor | CVE-2006-2899Proof of concept | Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, poestsoft · internetdisk | Medium6.5 | — | 3.8% | Jun 7, 2006 |
27Monitor | CVE-2010-5211No exploit | Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users to gain privileges via a Trojan horse patchani.dll file in the currestsoft · alsee | Medium6.9 | — | 0.4% | Sep 6, 2012 |
22Monitor | CVE-2022-21147No exploit | An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7.estsoft · alyac · CWE-823 | Medium5.5 | — | 0.7% | May 12, 2022 |
22Monitor | CVE-2022-43665No exploit | A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645.estsoft · alyac · CWE-823 | Medium5.5 | — | 0.3% | Feb 2, 2023 |
21Monitor | CVE-2005-3194No exploit | Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code vestsoft · alzip | Medium5.1 | — | 3.1% | Oct 14, 2005 |
18Monitor | CVE-2014-8494No exploit | ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local estsoft · alupdate · CWE-264 | Medium4.6 | — | 0.5% | Nov 3, 2014 |
- CVE-2008-270240Plan
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overw
CriticalCVSS 9.3Proof of conceptEPSS 11%estsoft · alftpJun 13, 2008
- CVE-2011-133639Monitor
Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.
CriticalCVSS 9.3No exploitEPSS 6%estsoft · alzipJul 7, 2011
- CVE-2012-031538Monitor
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a direc
CriticalCVSS 9.3No exploitEPSS 2%estsoft · alftpFeb 22, 2012
- CVE-2017-1132332Monitor
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device
HighCVSS 7.8No exploitEPSS 3%estsoft · alzipAug 19, 2017
- CVE-2019-1280731Monitor
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing
HighCVSS 7.8No exploitEPSS 2%estsoft · alzipAug 13, 2019
- CVE-2018-519631Monitor
Alzip Stack Overflow Vulnerability
HighCVSS 7.8No exploitEPSS 1%estsoft · alzipDec 21, 2018
- CVE-2019-1281031Monitor
A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39.
HighCVSS 7.8No exploitEPSS 1%estsoft · alseeAug 30, 2019
- CVE-2022-3254331Monitor
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.
HighCVSS 7.8No exploitEPSS 0%estsoft · alyacAug 5, 2022
- CVE-2022-2988631Monitor
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.
HighCVSS 7.8No exploitEPSS 0%estsoft · alyacAug 5, 2022
- CVE-2018-1002731Monitor
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific d
HighCVSS 7.8No exploitEPSS 0%estsoft · alzipMay 17, 2018
- CVE-2019-1280831Monitor
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission.
HighCVSS 7.8No exploitEPSS 0%estsoft · altoolsAug 13, 2019
- CVE-2006-289927Monitor
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, po
MediumCVSS 6.5Proof of conceptEPSS 4%estsoft · internetdiskJun 7, 2006
- CVE-2010-521127Monitor
Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users to gain privileges via a Trojan horse patchani.dll file in the curr
MediumCVSS 6.9No exploitEPSS 0%estsoft · alseeSep 6, 2012
- CVE-2022-2114722Monitor
An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7.
MediumCVSS 5.5No exploitEPSS 1%estsoft · alyacMay 12, 2022
- CVE-2022-4366522Monitor
A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645.
MediumCVSS 5.5No exploitEPSS 0%estsoft · alyacFeb 2, 2023
- CVE-2005-319421Monitor
Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code v
MediumCVSS 5.1No exploitEPSS 3%estsoft · alzipOct 14, 2005
- CVE-2014-849418Monitor
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local
MediumCVSS 4.6No exploitEPSS 0%estsoft · alupdateNov 3, 2014