WithSecure kayıtları
withsecure üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption5
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')4
- CWE-125 Out-of-bounds Read2
- CWE-269 Improper Privilege Management2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-43762İstismar yok | Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).withsecure · f-secure policy manager | Kritik9,8 | — | %1,4 | 22 Eyl 2023 |
39İzleyin | CVE-2022-38165İstismar yok | Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitwithsecure · f-secure policy manager · CWE-22 | Kritik9,8 | — | %0,9 | 17 Kas 2022 |
31İzleyin | CVE-2024-4454İstismar yok | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerabilitywithsecure · client security · CWE-59 | Yüksek7,8 | — | %0,4 | 22 May 2024 |
31İzleyin | CVE-2023-47172İstismar yok | Certain WithSecure products allow Local Privilege Escalation.withsecure · client security | Yüksek7,8 | — | %0,2 | 20 Kas 2023 |
30İzleyin | CVE-2024-27359İstismar yok | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive filCWE-835 | Yüksek7,5 | — | %0,7 | 26 Şub 2024 |
30İzleyin | CVE-2023-47263İstismar yok | Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.withsecure · client security | Yüksek7,5 | — | %0,7 | 15 Kas 2023 |
30İzleyin | CVE-2023-47264İstismar yok | Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).withsecure · client security · CWE-125 | Yüksek7,5 | — | %0,7 | 15 Kas 2023 |
30İzleyin | CVE-2023-42523İstismar yok | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.withsecure · client security · CWE-400 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2023-42524İstismar yok | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.withsecure · client security · CWE-835 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2023-42525İstismar yok | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.withsecure · client security · CWE-835 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2023-42526İstismar yok | Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.withsecure · client security · CWE-400 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2023-42521İstismar yok | Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.withsecure · client security · CWE-400 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2023-42520İstismar yok | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.withsecure · client security · CWE-400 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2023-42522İstismar yok | Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.withsecure · client security · CWE-400 | Yüksek7,5 | — | %0,6 | 18 Eyl 2023 |
30İzleyin | CVE-2022-28874İstismar yok | Multiple Denial-of-Service (DoS) Vulnerabilitiesf-secure · atlant · CWE-787 | Yüksek7,5 | — | %0,6 | 23 May 2022 |
30İzleyin | CVE-2024-45520İstismar yok | WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PECWE-125 | Yüksek7,5 | — | %0,5 | 1 Ara 2024 |
30İzleyin | CVE-2022-28884İstismar yok | Denial-of-Service (DoS) Vulnerabilitywithsecure · business suite · CWE-835 | Yüksek7,5 | — | %0,5 | 6 Eyl 2022 |
26İzleyin | CVE-2024-23764İstismar yok | Certain WithSecure products allow Local Privilege Escalation.withsecure · client security · CWE-269 | Orta6,7 | — | %0,2 | 8 Şub 2024 |
24İzleyin | CVE-2022-38162İstismar yok | Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an uwithsecure · f-secure policy manager · CWE-79 | Orta6,1 | — | %0,7 | 25 Eki 2022 |
24İzleyin | CVE-2023-43763İstismar yok | Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.withsecure · f-secure policy manager · CWE-79 | Orta6,1 | — | %0,4 | 22 Eyl 2023 |
23İzleyin | CVE-2024-27357İstismar yok | An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andCWE-269 | Orta5,8 | — | %0,2 | 26 Tem 2024 |
- CVE-2023-4376239İzleyin
Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend).
KritikCVSS 9,8İstismar yokEPSS %1withsecure · f-secure policy manager22 Eyl 2023
- CVE-2022-3816539İzleyin
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbit
KritikCVSS 9,8İstismar yokEPSS %1withsecure · f-secure policy manager17 Kas 2022
- CVE-2024-445431İzleyin
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0withsecure · client security22 May 2024
- CVE-2023-4717231İzleyin
Certain WithSecure products allow Local Privilege Escalation.
YüksekCVSS 7,8İstismar yokEPSS %0withsecure · client security20 Kas 2023
- CVE-2024-2735930İzleyin
Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive fil
YüksekCVSS 7,5İstismar yokEPSS %126 Şub 2024
- CVE-2023-4726330İzleyin
Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security15 Kas 2023
- CVE-2023-4726430İzleyin
Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS).
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security15 Kas 2023
- CVE-2023-4252330İzleyin
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2023-4252430İzleyin
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2023-4252530İzleyin
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2023-4252630İzleyin
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2023-4252130İzleyin
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2023-4252030İzleyin
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2023-4252230İzleyin
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file.
YüksekCVSS 7,5İstismar yokEPSS %1withsecure · client security18 Eyl 2023
- CVE-2022-2887430İzleyin
Multiple Denial-of-Service (DoS) Vulnerabilities
YüksekCVSS 7,5İstismar yokEPSS %1f-secure · atlant23 May 2022
- CVE-2024-4552030İzleyin
WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE
YüksekCVSS 7,5İstismar yokEPSS %11 Ara 2024
- CVE-2022-2888430İzleyin
Denial-of-Service (DoS) Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0withsecure · business suite6 Eyl 2022
- CVE-2024-2376426İzleyin
Certain WithSecure products allow Local Privilege Escalation.
OrtaCVSS 6,7İstismar yokEPSS %0withsecure · client security8 Şub 2024
- CVE-2022-3816224İzleyin
Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an u
OrtaCVSS 6,1İstismar yokEPSS %1withsecure · f-secure policy manager25 Eki 2022
- CVE-2023-4376324İzleyin
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint.
OrtaCVSS 6,1İstismar yokEPSS %0withsecure · f-secure policy manager22 Eyl 2023
- CVE-2024-2735723İzleyin
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and
OrtaCVSS 5,8İstismar yokEPSS %026 Tem 2024