| OSVDB ID | Disclosure Date | Title |
|
36727
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request packet (IRP), related to IOCTL (Input/Output Control) and "access validation of the address space."
|
2007-05-30
|
F-Secure Multiple Products Real-time Scanning Component Crafted IRP Packet Local Privilege Escalation
|
|
43222
Description:
(Description Provided by CVE) : Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
|
2008-03-17
|
F-Secure Multiple Products Archive Handling Unspecified Code Execution
|
|
13704
Description:
(Description Provided by CVE) : Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
|
2005-02-10
|
F-Secure Multiple Products ARJ Archive Handling Overflow
|
|
42903
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
|
2008-02-13
|
F-Secure Multiple Products Crafted CAB Archive Scanning Bypass
|
|
59589
Description:
Unknown / Incomplete
|
2009-10-27
|
F-Secure Multiple Products Crafted PDF File Scanning Bypass
|
|
42904
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to CVE-2008-0792.
|
2008-02-13
|
F-Secure Multiple Products Crafted RAR Archive Scanning Bypass
|
|
49189
Description:
(Description Provided by CVE) : Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
|
2008-10-21
|
F-Secure Multiple Products Crafted RPM File Handling Overflow
|
|
92957
Description:
F-Secure Anti-Virus for Mac, Safe Anywhere for Mac and Protection Service for Business (PSB) Workstation Security for Mac contain an unspecified flaw that may allow an attacker to cause the Mac OS X firewall to be disabled without user interaction or warning.
|
2012-12-12
|
F-Secure Multiple Products for Mac OS X Local Firewall Deactivation
|
|
63811
Description:
(Description Provided by CVE) : F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security 8 and earlier, and for E-mail and Server security 9 and earlier; Mac Protection build 8060 and earlier; Client Security 9 and earlier; and various Anti-Virus products for Windows, Linux, and Citrix; does not properly detect malware in crafted (1) 7Z, (2) GZIP, (3) CAB, or (4) RAR archives, which makes it easier for remote attackers to avoid detection.
|
2010-04-12
|
F-Secure Multiple Products Multiple Archive Files Detection Bypass
|
|
54686
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.
|
2009-05-06
|
F-Secure Multiple Products RAR Archive Scanning Bypass
|
|
70179
Description:
Multiple F-Secure products contain an unspecified error. This error may be exploited to cause the target to execute a binary file loaded on a disk resource accessible to the target system.
|
2010-12-15
|
F-Secure Multiple Products Remote Binary File Execution
|
|
92717
Description:
Multiple F-Secure products contain a flaw related to a legacy DLL component in an unspecified ActiveX control which may allow an attacker to connect to the ODBC drivers when using Internet Explorer. This may allow a context-dependent attacker to execute arbitrary SQL statements.
|
2013-04-24
|
F-Secure Multiple Products Unspecified ActiveX Control Arbitrary SQL Statement Execution
|
|
25937
Description:
(Description Provided by CVE) : Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.
|
2006-06-01
|
F-Secure Multiple Products Web Console Pre-authentication Overflow
|
|
54685
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.
|
2009-05-06
|
F-Secure Multiple Products ZIP Archive Scanning Bypass
|
|
65680
Description:
Unknown / Incomplete
|
2010-06-23
|
F-Secure Policy Manager Expect: Header XSS
|
|
12289
Description:
Policy Manager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when fsmsh.dll is called directly via an HTTP request, which will disclose the actual path information resulting in a loss of confidentiality.
|
2004-12-09
|
F-Secure Policy Manager fsmsh.dll Path Disclosure
|
|
36723
Description:
(Description Provided by CVE) : The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs.
|
2007-05-29
|
F-Secure Policy Manager Server fsmsh.dll Host Module Remote DoS
|
|
71118
Description:
The Web Reporting module in F-Secure Policy Manager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker accesses an invalid report, such as 'via report/infection-table.html' or 'report/productsummary-table.html', which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-02-24
|
F-Secure Policy Manager Web Reporting Module Invalid Report Access Path Disclosure
|
|
71117
Description:
The Web Reporting module in F-Secure Policy Manager contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input passed via the URL before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-24
|
F-Secure Policy Manager Web Reporting Module Unspecified XSS
|
|
20453
Description:
(Description Provided by CVE) : Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read files.
|
2005-11-02
|
F-Secure Products Web Console Traversal Arbitrary File Access
|
|
75188
Description:
(Description Provided by CVE) : F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that "the inability to catch these files are caused by lacking functionality rather than programming errors."
|
2010-10-18
|
F-Secure Protocol Handler (HCP) Malicious Code Execution Antivirus Scan Bypass
|
|
2646
Description:
(Description Provided by CVE) : SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.
|
2003-10-03
|
F-Secure SSH Malformed BER/DER Packet DoS
|
|
66589
Description:
Unknown / Incomplete
|
2010-07-20
|
F.E.A.R. / F.E.A.R. 2: Project Origin Lithtech Engine Crafted Packet Handling Memory Corruption
|
|
13232
Description:
(Description Provided by CVE) : The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
|
2005-01-27
|
f2c f2 Script Multiple Insecure Temporary File Handling
|
|
13231
Description:
(Description Provided by CVE) : The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
|
2005-01-27
|
f2c Translator Multiple File Insecure Temporary File Handling
|
|
59168
Description:
(Description Provided by CVE) : SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.
|
2002-06-26
|
f2html.pl File Name Parameter SQL Injection
|
|
61976
Description:
F2L 3000 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'Login Page' not properly sanitizing user-supplied input to an unspecified parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-25
|
F2L 3000 Login Page Unspecified Parameter SQL Injection
|
|
70313
Description:
F3Site contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'admin/editAdmin.php' script does not require multiple steps or explicit confirmation for sensitive transactions for the addition of administrator users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-04
|
F3Site admin/editAdmin.php Admin User Creation CSRF
|
|
34669
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.
|
2007-02-02
|
F3Site GIF86 Header Unrestricted File Upload Arbitrary Code Execution
|
|
61411
Description:
F3Site contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the mod/new.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'GLOBALS[nlang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2009-12-18
|
F3Site mod/new.php GLOBALS[nlang] Parameter Traversal Local File Inclusion
|