Записи ESTsoft
17 опубликованных записей вендора estsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-787 Out-of-bounds Write2
- CWE-823 Use of Out-of-range Pointer Offset2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-680 Integer Overflow to Buffer Overflow2
- CWE-426 Untrusted Search Path1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2008-2702Proof of concept | Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwestsoft · alftp · CWE-22 | Критическая9,3 | — | 10,7 % | 13 июн. 2008 г. |
39Наблюдать | CVE-2011-1336Эксплойта нет | Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.estsoft · alzip · CWE-119 | Критическая9,3 | — | 5,5 % | 7 июл. 2011 г. |
38Наблюдать | CVE-2012-0315Эксплойта нет | Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a direcestsoft · alftp | Критическая9,3 | — | 2,2 % | 22 февр. 2012 г. |
32Наблюдать | CVE-2017-11323Эксплойта нет | Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device estsoft · alzip · CWE-119 | Высокая7,8 | — | 3,0 % | 19 авг. 2017 г. |
31Наблюдать | CVE-2019-12807Эксплойта нет | Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing estsoft · alzip · CWE-119 | Высокая7,8 | — | 1,6 % | 13 авг. 2019 г. |
31Наблюдать | CVE-2018-5196Эксплойта нет | Alzip Stack Overflow Vulnerabilityestsoft · alzip · CWE-787 | Высокая7,8 | — | 1,4 % | 21 дек. 2018 г. |
31Наблюдать | CVE-2019-12810Эксплойта нет | A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39.estsoft · alsee · CWE-787 | Высокая7,8 | — | 1,2 % | 30 авг. 2019 г. |
31Наблюдать | CVE-2022-32543Эксплойта нет | An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.estsoft · alyac · CWE-680 | Высокая7,8 | — | 0,5 % | 5 авг. 2022 г. |
31Наблюдать | CVE-2022-29886Эксплойта нет | An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.estsoft · alyac · CWE-680 | Высокая7,8 | — | 0,5 % | 5 авг. 2022 г. |
31Наблюдать | CVE-2018-10027Эксплойта нет | ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific destsoft · alzip · CWE-426 | Высокая7,8 | — | 0,4 % | 17 мая 2018 г. |
31Наблюдать | CVE-2019-12808Эксплойта нет | ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission.estsoft · altools · CWE-264 | Высокая7,8 | — | 0,4 % | 13 авг. 2019 г. |
27Наблюдать | CVE-2006-2899Proof of concept | Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, poestsoft · internetdisk | Средняя6,5 | — | 3,8 % | 7 июн. 2006 г. |
27Наблюдать | CVE-2010-5211Эксплойта нет | Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users to gain privileges via a Trojan horse patchani.dll file in the currestsoft · alsee | Средняя6,9 | — | 0,4 % | 6 сент. 2012 г. |
22Наблюдать | CVE-2022-21147Эксплойта нет | An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7.estsoft · alyac · CWE-823 | Средняя5,5 | — | 0,7 % | 12 мая 2022 г. |
22Наблюдать | CVE-2022-43665Эксплойта нет | A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645.estsoft · alyac · CWE-823 | Средняя5,5 | — | 0,3 % | 2 февр. 2023 г. |
21Наблюдать | CVE-2005-3194Эксплойта нет | Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code vestsoft · alzip | Средняя5,1 | — | 3,1 % | 14 окт. 2005 г. |
18Наблюдать | CVE-2014-8494Эксплойта нет | ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local estsoft · alupdate · CWE-264 | Средняя4,6 | — | 0,5 % | 3 нояб. 2014 г. |
- CVE-2008-270240В плане
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overw
КритическаяCVSS 9,3Proof of conceptEPSS 11 %estsoft · alftp13 июн. 2008 г.
- CVE-2011-133639Наблюдать
Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %estsoft · alzip7 июл. 2011 г.
- CVE-2012-031538Наблюдать
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a direc
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %estsoft · alftp22 февр. 2012 г.
- CVE-2017-1132332Наблюдать
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %estsoft · alzip19 авг. 2017 г.
- CVE-2019-1280731Наблюдать
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %estsoft · alzip13 авг. 2019 г.
- CVE-2018-519631Наблюдать
Alzip Stack Overflow Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %estsoft · alzip21 дек. 2018 г.
- CVE-2019-1281031Наблюдать
A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %estsoft · alsee30 авг. 2019 г.
- CVE-2022-3254331Наблюдать
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %estsoft · alyac5 авг. 2022 г.
- CVE-2022-2988631Наблюдать
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %estsoft · alyac5 авг. 2022 г.
- CVE-2018-1002731Наблюдать
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific d
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %estsoft · alzip17 мая 2018 г.
- CVE-2019-1280831Наблюдать
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %estsoft · altools13 авг. 2019 г.
- CVE-2006-289927Наблюдать
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, po
СредняяCVSS 6,5Proof of conceptEPSS 4 %estsoft · internetdisk7 июн. 2006 г.
- CVE-2010-521127Наблюдать
Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users to gain privileges via a Trojan horse patchani.dll file in the curr
СредняяCVSS 6,9Эксплойта нетEPSS 0 %estsoft · alsee6 сент. 2012 г.
- CVE-2022-2114722Наблюдать
An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %estsoft · alyac12 мая 2022 г.
- CVE-2022-4366522Наблюдать
A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %estsoft · alyac2 февр. 2023 г.
- CVE-2005-319421Наблюдать
Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code v
СредняяCVSS 5,1Эксплойта нетEPSS 3 %estsoft · alzip14 окт. 2005 г.
- CVE-2014-849418Наблюдать
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local
СредняяCVSS 4,6Эксплойта нетEPSS 0 %estsoft · alupdate3 нояб. 2014 г.