F-Secure Anti-Virus vulnerabilities

34 known vulnerabilities affecting f-secure/f-secure_anti-virus.

Total CVEs
34
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH10MEDIUM19LOW1

Vulnerabilities

Page 2 of 2
CVE-2006-3490MEDIUMCVSS 5.0≤ 5.44≤ 5.52+9 more2006-07-10
CVE-2006-3490 [MEDIUM] CVE-2006-3490: F-Secure Anti-Virus 2003 through 2006 and other versions, Internet Security 2003 through 2006, and S F-Secure Anti-Virus 2003 through 2006 and other versions, Internet Security 2003 through 2006, and Service Platform for Service Providers 6.x and earlier does not scan files contained on removable media when "Scan network drives" is disabled, which allows remote attackers to bypass anti-virus controls.
nvd
CVE-2006-2838HIGHCVSS 7.6v6.402006-06-06
CVE-2006-2838 [HIGH] CVE-2006-2838: Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.
nvd
CVE-2006-0337HIGHCVSS 7.5v2.16v4.51+28 more2006-01-21
CVE-2006-0337 [HIGH] CVE-2006-0337: Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, includi Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.
nvd
CVE-2006-0338MEDIUMCVSS 5.0v4.51v4.52+23 more2006-01-21
CVE-2006-0338 [MEDIUM] CVE-2006-0338: Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for W Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.
nvd
CVE-2005-3664HIGHCVSS 7.5v4.502005-11-18
CVE-2005-3664 [HIGH] CVE-2005-3664: Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, An Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file.
nvd
CVE-2005-3468MEDIUMCVSS 5.0v6.402005-11-02
CVE-2005-3468 [MEDIUM] CVE-2005-3468: Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Ga Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read files.
nvd
CVE-2005-0350HIGHCVSS 7.5≤ 4.52≤ 4.61+11 more2005-05-02
CVE-2005-0350 [HIGH] CVE-2005-0350: Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows rem Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
nvd
CVE-2004-1762HIGHCVSS 7.5v4.50_hotfix_1v4.50_hotfix_2+1 more2004-12-31
CVE-2004-1762 [HIGH] CVE-2004-1762: Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober. Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.
nvd
CVE-2004-2442MEDIUMCVSS 5.0PoCv4.51v4.52+17 more2004-12-31
CVE-2004-2442 [MEDIUM] CVE-2004-2442: Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 an Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global he
nvd
CVE-2004-2405MEDIUMCVSS 6.4≤ 4.52≤ 5.42+4 more2004-12-31
CVE-2004-2405 [MEDIUM] CVE-2004-2405: Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and ear Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.
nvd
CVE-2004-2220MEDIUMCVSS 5.0v6.30v6.30_sr1+1 more2004-12-31
CVE-2004-2220 [MEDIUM] CVE-2004-2220: F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-p F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection.
nvd
CVE-2004-0830MEDIUMCVSS 5.0v6.01v6.2+1 more2004-09-09
CVE-2004-0830 [MEDIUM] CVE-2004-0830: The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.
nvd
CVE-2004-0234CRITICALCVSS 10.0v4.51v4.52+8 more2004-08-18
CVE-2004-0234 [CRITICAL] CWE-119 CVE-2004-0234: Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used i Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
nvd
CVE-2004-0235MEDIUMCVSS 6.4v4.51v4.52+8 more2004-08-18
CVE-2004-0235 [MEDIUM] CVE-2004-0235: Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to cr Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
nvd