flashfxp records
5 published records for vendor flashfxp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-255 Credentials Management Errors1
- CWE-427 Uncontrolled Search Path Element1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2012-4992Proof of concept | Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode striflashfxp · flashfxp · CWE-119 | Critical9.0 | — | 17.7% | Sep 19, 2012 |
34Monitor | CVE-2024-10068No exploit | OpenSight Software FlashFXP FlashFXP.exe uncontrolled search pathopensight software · flashfxp · CWE-427 | High8.5 | — | 0.2% | Oct 17, 2024 |
32Monitor | CVE-2007-0825Proof of concept | FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that containsflashfxp · flashfxp | High7.8 | — | 3.3% | Feb 7, 2007 |
25Monitor | CVE-2003-1483No exploit | FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.flashfxp · flashfxp · CWE-255 | Medium6.4 | — | 0.7% | Dec 31, 2003 |
8Monitor | CVE-2002-1939No exploit | FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of otheflashfxp · flashfxp | Low2.1 | — | 0.3% | Dec 31, 2002 |
- CVE-2012-499241Plan
Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode stri
CriticalCVSS 9.0Proof of conceptEPSS 18%flashfxp · flashfxpSep 19, 2012
- CVE-2024-1006834Monitor
OpenSight Software FlashFXP FlashFXP.exe uncontrolled search path
HighCVSS 8.5No exploitEPSS 0%opensight software · flashfxpOct 17, 2024
- CVE-2007-082532Monitor
FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains
HighCVSS 7.8Proof of conceptEPSS 3%flashfxp · flashfxpFeb 7, 2007
- CVE-2003-148325Monitor
FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.
MediumCVSS 6.4No exploitEPSS 1%flashfxp · flashfxpDec 31, 2003
- CVE-2002-19398Monitor
FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of othe
LowCVSS 2.1No exploitEPSS 0%flashfxp · flashfxpDec 31, 2002