Vulnerabilities > F Secure > F Secure Protection Service FOR Business

DATE CVE VULNERABILITY TITLE RISK
2009-02-06 CVE-2008-6085 Numeric Errors vulnerability in F-Secure products
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
network
high complexity
f-secure CWE-189
7.6
2008-03-20 CVE-2008-1412 Improper Input Validation vulnerability in F-Secure products
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
network
f-secure CWE-20
6.8
2008-02-22 CVE-2008-0910 Permissions, Privileges, and Access Controls vulnerability in F-Secure products
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive.
network
low complexity
f-secure CWE-264
7.5
2008-02-15 CVE-2008-0792 Permissions, Privileges, and Access Controls vulnerability in F-Secure products
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
network
f-secure CWE-264
5.8