Записи WithSecure
21 опубликованных записей вендора withsecure.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption5
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')4
- CWE-125 Out-of-bounds Read2
- CWE-269 Improper Privilege Management2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-43762Эксплойта нет | Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).withsecure · f-secure policy manager | Критическая9,8 | — | 1,4 % | 22 сент. 2023 г. |
39Наблюдать | CVE-2022-38165Эксплойта нет | Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitwithsecure · f-secure policy manager · CWE-22 | Критическая9,8 | — | 0,9 % | 17 нояб. 2022 г. |
31Наблюдать | CVE-2024-4454Эксплойта нет | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerabilitywithsecure · client security · CWE-59 | Высокая7,8 | — | 0,4 % | 22 мая 2024 г. |
31Наблюдать | CVE-2023-47172Эксплойта нет | Certain WithSecure products allow Local Privilege Escalation.withsecure · client security | Высокая7,8 | — | 0,2 % | 20 нояб. 2023 г. |
30Наблюдать | CVE-2024-27359Эксплойта нет | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive filCWE-835 | Высокая7,5 | — | 0,7 % | 26 февр. 2024 г. |
30Наблюдать | CVE-2023-47263Эксплойта нет | Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.withsecure · client security | Высокая7,5 | — | 0,7 % | 15 нояб. 2023 г. |
30Наблюдать | CVE-2023-47264Эксплойта нет | Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).withsecure · client security · CWE-125 | Высокая7,5 | — | 0,7 % | 15 нояб. 2023 г. |
30Наблюдать | CVE-2023-42523Эксплойта нет | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.withsecure · client security · CWE-400 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2023-42524Эксплойта нет | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.withsecure · client security · CWE-835 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2023-42525Эксплойта нет | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.withsecure · client security · CWE-835 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2023-42526Эксплойта нет | Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.withsecure · client security · CWE-400 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2023-42521Эксплойта нет | Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.withsecure · client security · CWE-400 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2023-42520Эксплойта нет | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.withsecure · client security · CWE-400 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2023-42522Эксплойта нет | Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.withsecure · client security · CWE-400 | Высокая7,5 | — | 0,6 % | 18 сент. 2023 г. |
30Наблюдать | CVE-2022-28874Эксплойта нет | Multiple Denial-of-Service (DoS) Vulnerabilitiesf-secure · atlant · CWE-787 | Высокая7,5 | — | 0,6 % | 23 мая 2022 г. |
30Наблюдать | CVE-2024-45520Эксплойта нет | WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PECWE-125 | Высокая7,5 | — | 0,5 % | 1 дек. 2024 г. |
30Наблюдать | CVE-2022-28884Эксплойта нет | Denial-of-Service (DoS) Vulnerabilitywithsecure · business suite · CWE-835 | Высокая7,5 | — | 0,5 % | 6 сент. 2022 г. |
26Наблюдать | CVE-2024-23764Эксплойта нет | Certain WithSecure products allow Local Privilege Escalation.withsecure · client security · CWE-269 | Средняя6,7 | — | 0,2 % | 8 февр. 2024 г. |
24Наблюдать | CVE-2022-38162Эксплойта нет | Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an uwithsecure · f-secure policy manager · CWE-79 | Средняя6,1 | — | 0,7 % | 25 окт. 2022 г. |
24Наблюдать | CVE-2023-43763Эксплойта нет | Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.withsecure · f-secure policy manager · CWE-79 | Средняя6,1 | — | 0,4 % | 22 сент. 2023 г. |
23Наблюдать | CVE-2024-27357Эксплойта нет | An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andCWE-269 | Средняя5,8 | — | 0,2 % | 26 июл. 2024 г. |
- CVE-2023-4376239Наблюдать
Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %withsecure · f-secure policy manager22 сент. 2023 г.
- CVE-2022-3816539Наблюдать
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %withsecure · f-secure policy manager17 нояб. 2022 г.
- CVE-2024-445431Наблюдать
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %withsecure · client security22 мая 2024 г.
- CVE-2023-4717231Наблюдать
Certain WithSecure products allow Local Privilege Escalation.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %withsecure · client security20 нояб. 2023 г.
- CVE-2024-2735930Наблюдать
Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive fil
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %26 февр. 2024 г.
- CVE-2023-4726330Наблюдать
Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security15 нояб. 2023 г.
- CVE-2023-4726430Наблюдать
Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security15 нояб. 2023 г.
- CVE-2023-4252330Наблюдать
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2023-4252430Наблюдать
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2023-4252530Наблюдать
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2023-4252630Наблюдать
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2023-4252130Наблюдать
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2023-4252030Наблюдать
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2023-4252230Наблюдать
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %withsecure · client security18 сент. 2023 г.
- CVE-2022-2887430Наблюдать
Multiple Denial-of-Service (DoS) Vulnerabilities
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %f-secure · atlant23 мая 2022 г.
- CVE-2024-4552030Наблюдать
WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %1 дек. 2024 г.
- CVE-2022-2888430Наблюдать
Denial-of-Service (DoS) Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %withsecure · business suite6 сент. 2022 г.
- CVE-2024-2376426Наблюдать
Certain WithSecure products allow Local Privilege Escalation.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %withsecure · client security8 февр. 2024 г.
- CVE-2022-3816224Наблюдать
Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an u
СредняяCVSS 6,1Эксплойта нетEPSS 1 %withsecure · f-secure policy manager25 окт. 2022 г.
- CVE-2023-4376324Наблюдать
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %withsecure · f-secure policy manager22 сент. 2023 г.
- CVE-2024-2735723Наблюдать
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and
СредняяCVSS 5,8Эксплойта нетEPSS 0 %26 июл. 2024 г.