Vulnerabilities > F Secure > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-25 CVE-2022-28871 Allocation of Resources Without Limits or Throttling vulnerability in F-Secure Atlant
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scanning larger packages/fuzzed files consume too much memory eventually can crash the scanning engine.
network
low complexity
f-secure CWE-770
7.5
2022-03-10 CVE-2021-44750 Unspecified vulnerability in F-Secure products
An arbitrary code execution vulnerability was found in the F-Secure Support Tool.
local
low complexity
f-secure
7.3
2021-09-28 CVE-2021-33600 Reachable Assertion vulnerability in F-Secure Internet Gatekeeper
A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper.
network
low complexity
f-secure CWE-617
7.5
2021-09-28 CVE-2021-33601 Unspecified vulnerability in F-Secure Internet Gatekeeper
A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper.
network
low complexity
f-secure
8.8
2020-06-23 CVE-2020-14978 Unspecified vulnerability in F-Secure Safe 17.7
An issue was discovered in F-Secure SAFE 17.7 on macOS.
network
high complexity
f-secure
8.1
2020-06-23 CVE-2020-14977 Unspecified vulnerability in F-Secure Safe 17.7
An issue was discovered in F-Secure SAFE 17.7 on macOS.
network
high complexity
f-secure
8.1
2019-05-17 CVE-2019-11644 Uncontrolled Search Path Element vulnerability in F-Secure products
In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer Protection Standard and Premium before 19.3, a local user can escalate their privileges through a DLL hijacking attack against the installer.
local
low complexity
f-secure CWE-427
7.8
2018-06-13 CVE-2018-10403 Improper Certificate Validation vulnerability in F-Secure Xfence
An issue was discovered in F-Secure XFENCE and Little Flocker.
local
low complexity
f-secure CWE-295
7.8
2017-08-02 CVE-2015-8264 Untrusted Search Path vulnerability in F-Secure Online Scanner
Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as F-SecureOnlineScanner.exe.
local
low complexity
f-secure CWE-426
7.8
2017-03-11 CVE-2017-6466 Improper Input Validation vulnerability in F-Secure Software Updater 2.20
F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform file integrity validation after download.
network
high complexity
f-secure CWE-20
8.1