WithSecure records
21 published records for vendor withsecure.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption5
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')4
- CWE-125 Out-of-bounds Read2
- CWE-269 Improper Privilege Management2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-43762No exploit | Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).withsecure · f-secure policy manager | Critical9.8 | — | 1.4% | Sep 22, 2023 |
39Monitor | CVE-2022-38165No exploit | Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitwithsecure · f-secure policy manager · CWE-22 | Critical9.8 | — | 0.9% | Nov 17, 2022 |
31Monitor | CVE-2024-4454No exploit | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerabilitywithsecure · client security · CWE-59 | High7.8 | — | 0.4% | May 22, 2024 |
31Monitor | CVE-2023-47172No exploit | Certain WithSecure products allow Local Privilege Escalation.withsecure · client security | High7.8 | — | 0.2% | Nov 20, 2023 |
30Monitor | CVE-2024-27359No exploit | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive filCWE-835 | High7.5 | — | 0.7% | Feb 26, 2024 |
30Monitor | CVE-2023-47263No exploit | Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.withsecure · client security | High7.5 | — | 0.7% | Nov 15, 2023 |
30Monitor | CVE-2023-47264No exploit | Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).withsecure · client security · CWE-125 | High7.5 | — | 0.7% | Nov 15, 2023 |
30Monitor | CVE-2023-42523No exploit | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.withsecure · client security · CWE-400 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2023-42524No exploit | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.withsecure · client security · CWE-835 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2023-42525No exploit | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.withsecure · client security · CWE-835 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2023-42526No exploit | Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.withsecure · client security · CWE-400 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2023-42521No exploit | Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.withsecure · client security · CWE-400 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2023-42520No exploit | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.withsecure · client security · CWE-400 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2023-42522No exploit | Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.withsecure · client security · CWE-400 | High7.5 | — | 0.6% | Sep 18, 2023 |
30Monitor | CVE-2022-28874No exploit | Multiple Denial-of-Service (DoS) Vulnerabilitiesf-secure · atlant · CWE-787 | High7.5 | — | 0.6% | May 23, 2022 |
30Monitor | CVE-2024-45520No exploit | WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PECWE-125 | High7.5 | — | 0.5% | Dec 1, 2024 |
30Monitor | CVE-2022-28884No exploit | Denial-of-Service (DoS) Vulnerabilitywithsecure · business suite · CWE-835 | High7.5 | — | 0.5% | Sep 6, 2022 |
26Monitor | CVE-2024-23764No exploit | Certain WithSecure products allow Local Privilege Escalation.withsecure · client security · CWE-269 | Medium6.7 | — | 0.2% | Feb 8, 2024 |
24Monitor | CVE-2022-38162No exploit | Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an uwithsecure · f-secure policy manager · CWE-79 | Medium6.1 | — | 0.7% | Oct 25, 2022 |
24Monitor | CVE-2023-43763No exploit | Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.withsecure · f-secure policy manager · CWE-79 | Medium6.1 | — | 0.4% | Sep 22, 2023 |
23Monitor | CVE-2024-27357No exploit | An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andCWE-269 | Medium5.8 | — | 0.2% | Jul 26, 2024 |
- CVE-2023-4376239Monitor
Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).
CriticalCVSS 9.8No exploitEPSS 1%withsecure · f-secure policy managerSep 22, 2023
- CVE-2022-3816539Monitor
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbit
CriticalCVSS 9.8No exploitEPSS 1%withsecure · f-secure policy managerNov 17, 2022
- CVE-2024-445431Monitor
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%withsecure · client securityMay 22, 2024
- CVE-2023-4717231Monitor
Certain WithSecure products allow Local Privilege Escalation.
HighCVSS 7.8No exploitEPSS 0%withsecure · client securityNov 20, 2023
- CVE-2024-2735930Monitor
Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive fil
HighCVSS 7.5No exploitEPSS 1%Feb 26, 2024
- CVE-2023-4726330Monitor
Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securityNov 15, 2023
- CVE-2023-4726430Monitor
Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).
HighCVSS 7.5No exploitEPSS 1%withsecure · client securityNov 15, 2023
- CVE-2023-4252330Monitor
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2023-4252430Monitor
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2023-4252530Monitor
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2023-4252630Monitor
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2023-4252130Monitor
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2023-4252030Monitor
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2023-4252230Monitor
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.
HighCVSS 7.5No exploitEPSS 1%withsecure · client securitySep 18, 2023
- CVE-2022-2887430Monitor
Multiple Denial-of-Service (DoS) Vulnerabilities
HighCVSS 7.5No exploitEPSS 1%f-secure · atlantMay 23, 2022
- CVE-2024-4552030Monitor
WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE
HighCVSS 7.5No exploitEPSS 1%Dec 1, 2024
- CVE-2022-2888430Monitor
Denial-of-Service (DoS) Vulnerability
HighCVSS 7.5No exploitEPSS 0%withsecure · business suiteSep 6, 2022
- CVE-2024-2376426Monitor
Certain WithSecure products allow Local Privilege Escalation.
MediumCVSS 6.7No exploitEPSS 0%withsecure · client securityFeb 8, 2024
- CVE-2022-3816224Monitor
Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an u
MediumCVSS 6.1No exploitEPSS 1%withsecure · f-secure policy managerOct 25, 2022
- CVE-2023-4376324Monitor
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.
MediumCVSS 6.1No exploitEPSS 0%withsecure · f-secure policy managerSep 22, 2023
- CVE-2024-2735723Monitor
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and
MediumCVSS 5.8No exploitEPSS 0%Jul 26, 2024