Vulnerabilities > F Prot

DATE CVE VULNERABILITY TITLE RISK
2009-05-22 CVE-2009-1783 Improper Input Validation vulnerability in F-Prot Antivirus, F-Prot Aves and F-Prot Milter
Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
network
low complexity
f-prot CWE-20
critical
10.0
2008-12-29 CVE-2008-5747 Resource Management Errors vulnerability in F-Prot Antivirus 4.6.8
F-Prot 4.6.8 for GNU/Linux allows remote attackers to bypass anti-virus protection via a crafted ELF program with a "corrupted" header that still allows the program to be executed.
network
low complexity
f-prot CWE-399
5.0
2008-08-04 CVE-2008-3447 Resource Management Errors vulnerability in F-Prot Antivirus and Scanning Engine
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.
network
low complexity
f-prot CWE-399
5.0
2008-07-21 CVE-2008-3244 Improper Input Validation vulnerability in F-Prot Antivirus and Scanning Engine
The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read.
network
f-prot CWE-20
4.3
2008-07-21 CVE-2008-3243 Improper Input Validation vulnerability in F-Prot Antivirus and Scanning Engine
Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an ASPack-compressed file, which triggers an engine crash.
network
f-prot CWE-20
4.3
2006-12-10 CVE-2006-6407 Unspecified vulnerability in F-Prot Antivirus 4.6.6
F-Prot Antivirus for Linux x86 Mail Servers 4.6.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.
network
low complexity
f-prot
5.0
2006-12-05 CVE-2006-6293 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in F-Prot Antivirus
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file.
network
low complexity
f-prot CWE-119
7.5