VYPR

Vendor CVEs

F-Secure

All CVEs

132 total · sorted by risk
  • CVE-2022-38165CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.

  • CVE-2020-14978HigJun 23, 2020
    risk 0.53cvss 8.1epss 0.03

    An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

  • CVE-2020-14977HigJun 23, 2020
    risk 0.53cvss 8.1epss 0.03

    An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the…

  • CVE-2017-6466HigMar 11, 2017
    risk 0.53cvss 8.1epss 0.02

    F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform file integrity validation after download. Man-in-the-middle attackers can replace the file with their own executable which will be…

  • CVE-2024-7240HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    F-Secure Total Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability. The…

  • CVE-2023-43766HigSep 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…

  • CVE-2020-10648HigMar 19, 2020
    risk 0.51cvss 7.8epss 0.01

    Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

  • CVE-2019-11644HigMay 17, 2019
    risk 0.51cvss 7.8epss 0.01

    In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer…

  • CVE-2018-10403HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is…

  • CVE-2018-6209HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.

  • CVE-2018-6208HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x22000d.

  • CVE-2018-6207HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.

  • CVE-2018-6205HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220009.

  • CVE-2018-6204HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.

  • CVE-2015-8264HigAug 2, 2017
    risk 0.51cvss 7.8epss 0.03

    Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as F-SecureOnlineScanner.exe.

  • CVE-2023-49322HigNov 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements…

  • CVE-2023-43767HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client…

  • CVE-2023-43765HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for…

  • CVE-2023-43761HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15,…

  • CVE-2023-43760HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for…

  • CVE-2022-38166HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service.

  • CVE-2021-33601HigSep 28, 2021
    risk 0.49cvss 7.6epss 0.01

    A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

  • CVE-2022-38164MedNov 7, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL.

  • CVE-2021-44750MedMar 10, 2022
    risk 0.42cvss 6.4epss 0.01

    An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands.

  • CVE-2018-6324MedFeb 16, 2018
    risk 0.40cvss 6.1epss 0.01

    F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.

  • CVE-2018-6189MedFeb 16, 2018
    risk 0.40cvss 6.1epss 0.01

    F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested metadata tags for assets" issue.

  • CVE-2021-44749MedMar 6, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful…

  • CVE-2021-44748MedMar 6, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User…

  • CVE-2021-40833MedNov 26, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

  • CVE-2021-40832MedOct 8, 2021
    risk 0.36cvss 5.5epss 0.01

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result…

  • CVE-2021-33603MedOct 8, 2021
    risk 0.36cvss 5.5epss 0.01

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in…

  • CVE-2021-33602MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in…

  • CVE-2020-9342MedFeb 22, 2020
    risk 0.36cvss 5.5epss 0.02

    The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.

  • CVE-2022-47524MedDec 23, 2022
    risk 0.35cvss 5.4epss 0.00

    F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.

  • CVE-2021-33600MedSep 28, 2021
    risk 0.35cvss 5.4epss 0.01

    A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this…

  • CVE-2023-49321MedNov 27, 2023
    risk 0.34cvss 5.3epss 0.01

    Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements…

  • CVE-2021-44747MedMar 1, 2022
    risk 0.30cvss 4.6epss 0.01

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the Fmlib component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in…

  • CVE-2021-40837MedFeb 9, 2022
    risk 0.30cvss 4.6epss 0.01

    A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in…

  • CVE-2021-40836MedDec 22, 2021
    risk 0.30cvss 4.6epss 0.00

    A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

  • CVE-2021-40835MedDec 16, 2021
    risk 0.30cvss 4.6epss 0.01

    An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from…

  • CVE-2021-33599MedSep 7, 2021
    risk 0.30cvss 4.6epss 0.00

    A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack will result in…

  • CVE-2021-33598MedAug 23, 2021
    risk 0.30cvss 4.6epss 0.01

    A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result…

  • CVE-2023-1491MedMar 18, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the library MaxCryptMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is…

  • CVE-2023-1490MedMar 18, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the library SDActMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. An attack has to…

  • CVE-2022-45871MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.00

    A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing ICAP request. The exploit can be triggered remotely by an attacker.

  • CVE-2022-28887MedOct 12, 2022
    risk 0.28cvss 4.3epss 0.00

    Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.

  • CVE-2022-28886MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.00

    A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine

  • CVE-2022-28885MedSep 6, 2022
    risk 0.28cvss 4.3epss 0.00

    A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing the scanning request.

  • CVE-2022-28884MedSep 6, 2022
    risk 0.28cvss 4.3epss 0.00

    A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.

  • CVE-2022-28882MedAug 23, 2022
    risk 0.28cvss 4.3epss 0.00

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker.

Page 1 of 3