| OSVDB ID | Disclosure Date | Title |
|
79420
Description:
F*EX (Frams' Fast File EXchange) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' and 'from' parameters upon submission to the '/fup' script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-21
|
F*EX (Frams' Fast File EXchange) /fup Multiple Parameter XSS
|
|
73448
Description:
(Description Provided by CVE) : Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.
|
2011-06-13
|
F*EX (Frams' Fast File EXchange) Authentication ID Validation Weakness Remote Authentication Bypass
|
|
84085
Description:
F*EX (Frams' Fast File EXchange) contains a flaw in 'dop' that is triggered when an error occurs during the handling of the lib or spool directories. No further details have been provided.
|
2011-08-08
|
F*EX (Frams' Fast File EXchange) dop lib / spool Directory Handling Unspecified Issue
|
|
84082
Description:
F*EX (Frams' Fast File EXchange) contains a flaw that may allow a local denial of service. The issue is triggered when handling loops created by a symlink in the dop subsystem. This may allow a local attacker to cause a loss of availability for the program.
|
2009-02-15
|
F*EX (Frams' Fast File EXchange) dop Symlink Loop Handling Local DoS
|
|
84084
Description:
F*EX (Frams' Fast File EXchange) contains a flaw that is triggered during the handling of a forwarded fup file. No further details have been provided.
|
2011-06-05
|
F*EX (Frams' Fast File EXchange) fup Forward File Handling Unspecified Issue
|
|
84056
Description:
F*EX (Frams' Fast File EXchange) contains an unspecified flaw that is triggered when an error occurs in MIME-type during the handling of text and html. No further details have been provided.
|
2012-02-15
|
F*EX (Frams' Fast File EXchange) MIME-type text/html Handling Unspecified Issue
|
|
83897
Description:
F*EX (Frams' Fast File EXchange) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-07-15
|
F*EX (Frams' Fast File EXchange) Unspecified XSS
|
|
80421
Description:
F-Prot Antivirus contains a flaw related to the anti-virus / anti-malware scanning functionality. This may allow a context-dependent attacker to use a specially crafted ELF file in order to bypass the scanning functionality, allowing for the delivery of malware.
|
2012-03-19
|
F-Prot Antivirus Malformed ELF File Handling Scan Bypass
|
|
80451
Description:
F-Prot Antivirus contains a flaw related to the anti-virus / anti-malware scanning functionality. The issue is triggered when a context-dependent attacker sends a malformed RAR file with an initial MZ sequence. This type of file will not be handled properly by the software and may allow an attacker to bypass the scanning allowing for the delivery of malware.
|
2012-03-19
|
F-Prot Antivirus Malformed RAR File Handling Scan Bypass
|
|
80406
Description:
F-Prot Antivirus contains a flaw related to the anti-virus / anti-malware scanning functionality. This may allow a context-dependent attacker to use a specially crafted TAR file in order to bypass the scanning functionality, allowing for the delivery of malware.
|
2012-03-19
|
F-Prot Antivirus Malformed TAR File Handling Scan Bypass
|
|
80494
Description:
F-Prot Antivirus contains a flaw related to the anti-virus / anti-malware scanning functionality. The issue is triggered when a context-dependent attacker sends a malformed TGZ (.tar.gz) file with stray bytes at the end. This type of file will not be handled properly by the software and may allow an attacker to bypass the scanning allowing for the delivery of malware.
|
2012-03-19
|
F-Prot Antivirus Malformed TGZ File Handling Scan Bypass
|
|
4183
Description:
(Description Provided by CVE) : Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.
|
2004-03-10
|
F-Secure Anti-Virus (FSAV) for Linux Sober.D Detection Bypass
|
|
36725
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
|
2007-05-30
|
F-Secure Anti-Virus ARJ File Handling DoS
|
|
34764
Description:
(Description Provided by CVE) : Format string vulnerability in F-Secure Anti-Virus Client Security 6.02 allows local users to cause a denial of service and possibly gain privileges via format string specifiers in the Management Server name field on the Communication settings page.
|
2007-03-18
|
F-Secure Anti-Virus Client Security Management Server Communications Settings Format String
|
|
36728
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
|
2007-06-19
|
F-Secure Anti-Virus Crafted LHA File Scanning Bypass
|
|
36729
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
|
2007-06-19
|
F-Secure Anti-Virus Crafted RAR File Scanning Bypass
|
|
22633
Description:
F-Secure Anti Virus products contain a flaw that may allow malicious code to bypass the scanning engine. The issue is triggered when specially crafted RAR or ZIP archives are processed by the scanning engine, resulting in a loss of integrity.
|
2006-01-19
|
F-Secure Anti-Virus Crafted ZIP/RAR Scanner Bypass
|
|
19913
Description:
A remote overflow exists in F-Secure Anti-Virus for Linux. The Anti-Virus engine fails to perform proper bounds checking resulting in a heap-based buffer overflow. With a specially crafted CHM file, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-10-10
|
F-Secure Anti-Virus for Linux CHM File Parsing Overflow
|
|
9818
Description:
F-Secure Anti-Virus for Microsoft Exchange contains a flaw that may allow a remote denial of service. The issue is triggered due to the parsing of malformed packets on port 18,971, which causes the application to crash with an access violation error and will result in loss of availability for the server.
|
2004-09-09
|
F-Secure Anti-Virus For Microsoft Exchange Content Scanner Server Exception Handling DoS
|
|
11395
Description:
F-Secure Anti-Virus for Microsoft Exchange contains a flaw that may allow a malicious user to bypass anti-virus protection. The issue may be triggered by nesting a malicious password-protected file inside a ZIP archive. The flaw is not directly exploitable but may lead to a more serious impact.
|
2004-11-03
|
F-Secure Anti-Virus for Microsoft Exchange Nested Password Protected Archives Bypass
|
|
4962
Description:
F-Secure for MIMEsweeper contains a flaw that may allow a malicious worm to avoid detection. The issue is triggered when a Sober.D worm propagates itself in a zip file. It is possible that the flaw may allow malicious code to pass resulting in a loss of confidentiality, integrity, and/or availability.
|
2004-04-06
|
F-Secure Anti-Virus for MIMEsweeper Sober.D Detection Bypass
|
|
41377
Description:
(Description Provided by CVE) : F-Secure Anti-Virus for Windows Servers 7.0 64-bit edition allows local users to bypass virus scanning by using the system32 directory to store a crafted (1) archive or (2) packed executable. NOTE: in many environments, this does not cross privilege boundaries because any process able to write to system32 could also shut off F-Secure Anti-Virus.
|
2007-09-27
|
F-Secure Anti-Virus for Windows system32 Directory Crafted File Detection Bypass
|
|
36726
Description:
(Description Provided by CVE) : Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
|
2007-05-30
|
F-Secure Anti-Virus FSG File Handling DoS
|
|
20552
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named diag.cgi in the current working directory, and executes the SUID script diag_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway diag_suid.cgi Local Privilege Escalation
|
|
20549
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named dns.cgi in the current working directory, and executes the SUID script dns_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway dns_suid.cgi Local Privilege Escalation
|
|
20539
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named edittmpl.cgi in the current working directory, and executes the SUID script edittmpl_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway edittmpl_suid.cgi Local Privilege Escalation
|
|
20544
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named edituserdb.cgi in the current working directory, and executes the SUID script edituserdb_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway edituserdb_suid.cgi Local Privilege Escalation
|
|
20542
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named gateway.cgi in the current working directory, and executes the SUID script gateway_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway gateway_suid.cgi Local Privilege Escalation
|
|
20543
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named halt.cgi in the current working directory, and executes the SUID script halt_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway halt_suid.cgi Local Privilege Escalation
|
|
20541
Description:
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named hostname.cgi in the current working directory, and executes the SUID script hostname_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.
|
2005-11-07
|
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway hostname_suid.cgi Local Privilege Escalation
|