Skip to content
Noroxi

WithSecure records

21 published records for vendor withsecure.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

21 records
  • Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).

    CriticalCVSS 9.8No exploitEPSS 1%

    withsecure · f-secure policy managerSep 22, 2023

  • Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbit

    CriticalCVSS 9.8No exploitEPSS 1%

    withsecure · f-secure policy managerNov 17, 2022

  • CVE-2024-4454
    31Monitor

    WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    withsecure · client securityMay 22, 2024

  • Certain WithSecure products allow Local Privilege Escalation.

    HighCVSS 7.8No exploitEPSS 0%

    withsecure · client securityNov 20, 2023

  • Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive fil

    HighCVSS 7.5No exploitEPSS 1%

    Feb 26, 2024

  • Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securityNov 15, 2023

  • Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securityNov 15, 2023

  • Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.

    HighCVSS 7.5No exploitEPSS 1%

    withsecure · client securitySep 18, 2023

  • Multiple Denial-of-Service (DoS) Vulnerabilities

    HighCVSS 7.5No exploitEPSS 1%

    f-secure · atlantMay 23, 2022

  • WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE

    HighCVSS 7.5No exploitEPSS 1%

    Dec 1, 2024

  • Denial-of-Service (DoS) Vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    withsecure · business suiteSep 6, 2022

  • Certain WithSecure products allow Local Privilege Escalation.

    MediumCVSS 6.7No exploitEPSS 0%

    withsecure · client securityFeb 8, 2024

  • Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an u

    MediumCVSS 6.1No exploitEPSS 1%

    withsecure · f-secure policy managerOct 25, 2022

  • Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.

    MediumCVSS 6.1No exploitEPSS 0%

    withsecure · f-secure policy managerSep 22, 2023

  • An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and

    MediumCVSS 5.8No exploitEPSS 0%

    Jul 26, 2024