Vulnerabilities > F Secure > F Secure Anti Virus > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-06-20 CVE-2007-3300 Anti-Virus Products LHA and RAR Archives Scan Bypass vulnerability in F-Secure
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
network
f-secure
critical
9.3
2007-05-31 CVE-2007-2967 Improper Input Validation vulnerability in F-Secure products
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
network
low complexity
f-secure CWE-20
critical
10.0
2006-12-10 CVE-2006-6409 Unspecified vulnerability in F-Secure Anti-Virus 4.65
F-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass virus detection, by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.
network
low complexity
f-secure
critical
10.0
2004-08-18 CVE-2004-0234 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
10.0