VYPR
Vendor

Altools

Products
6
CVEs
11
Across products
11
Status
Private

Products

6

Recent CVEs

11
  • CVE-2018-5196HigDec 21, 2018
    risk 0.57cvss 8.8epss 0.01

    Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.

  • CVE-2019-12808HigAug 13, 2019
    risk 0.51cvss 7.8epss 0.00

    ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulnerability and execute arbitrary code with system privileges.

  • CVE-2019-12807HigAug 13, 2019
    risk 0.51cvss 7.8epss 0.02

    Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an attacker could execution…

  • CVE-2020-7809MedMay 15, 2020
    risk 0.29cvss 4.4epss 0.01

    ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by improper validation of user input. A remote attacker could exploit this vulnerability by tricking the victim to open ALSong Album(sab) file.

  • CVE-2008-2702Jun 13, 2008
    risk 0.04cvss epss 0.11

    Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for…

  • CVE-2012-0315Feb 22, 2012
    risk 0.00cvss epss 0.02

    Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access…

  • CVE-2011-1336Jul 7, 2011
    risk 0.00cvss epss 0.06

    Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.

  • CVE-2007-4549Aug 28, 2007
    risk 0.00cvss epss 0.05

    Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrary code via an ALPass DB (APW) file containing (1) a long file-key or (2) a "Site Information and Folder entry" with a ciphertext_length value much larger than…

  • CVE-2007-4550Aug 28, 2007
    risk 0.00cvss epss 0.04

    Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an fnm field in a folder-name record in an ALPASS DB (APW) file.

  • CVE-2006-5950Nov 17, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors related to the REN command, probably due to response messages. NOTE: the provenance of this information…

  • CVE-2006-5949Nov 17, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request. NOTE: the provenance of this information is unknown; details are obtained…