VendorsF-Secureinternet_gatekeeperall versions
Vulnerabilities

F-Secure Internet Gatekeeper for Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2004-0234
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
Published 2004-05-05 · Modified
10.0EPSS 0.103
CVE-2007-2967
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
Published 2007-05-31 · Modified
10.0EPSS 0.048
CVE-2007-3300
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
Published 2007-06-20 · Modified
9.3EPSS 0.037
CVE-2021-33601
Arbitrary Code Execution in Web Interface of F-Secure Internet Gatekeeper
Published 2021-09-28 · Modified
8.8EPSS 0.009
CVE-2006-2838
Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.
Published 2006-06-06 · Modified
7.6EPSS 0.057
CVE-2006-0337
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.
Published 2006-01-21 · Modified
7.5EPSS 0.058
CVE-2007-2966
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
Published 2007-05-31 · Modified
7.5EPSS 0.052
CVE-2005-0350
Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
Published 2005-02-11 · Modified
7.5EPSS 0.033
CVE-2003-1015
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2003-1016
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2003-1014
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use multiple MIME fields with the same name, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2004-0162
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2004-0052
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2004-0161
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2004-0053
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2004-0051
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.
Published 2004-09-24 · Modified
7.5EPSS 0.024
CVE-2021-33600
Denial of Service Vulnerability in Web Interface of F-Secure Internet Gatekeeper
Published 2021-09-28 · Modified
7.5EPSS 0.006
CVE-2022-28883
Denial-of-Service (DoS) Vulnerability
Published 2022-08-23 · Modified
7.5EPSS 0.006
CVE-2022-28880
Denial-of-Service (DoS) Vulnerability
Published 2022-08-05 · Modified
7.5EPSS 0.005
CVE-2022-28881
Denial-of-Service (DoS) Vulnerability
Published 2022-08-10 · Modified
7.5EPSS 0.005
CVE-2022-28884
Denial-of-Service (DoS) Vulnerability
Published 2022-09-06 · Modified
7.5EPSS 0.005
CVE-2022-28876
Denial-of-Service (DoS) Vulnerability
Published 2022-07-14 · Modified
7.5EPSS 0.005
CVE-2022-28878
Denial-of-Service (DoS) Vulnerability
Published 2022-07-22 · Modified
7.5EPSS 0.005
CVE-2022-28879
Denial-of-Service (DoS) Vulnerability
Published 2022-07-22 · Modified
7.5EPSS 0.005
CVE-2022-28882
Denial-of-Service (DoS) Vulnerability
Published 2022-08-23 · Modified
7.5EPSS 0.004
CVE-2022-28887
Multiple Denial of Service Vulnerability
Published 2022-10-12 · Modified
7.5EPSS 0.004
CVE-2005-3546
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
Published 2005-11-16 · Modified
7.21 PoCEPSS 0.008
CVE-2007-2965
Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request packet (IRP), related to IOCTL (Input/Output Control) and "access validation of the address space."
Published 2007-05-31 · Modified
7.2EPSS 0.004
CVE-2009-1782
Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.
Published 2009-05-22 · Modified
6.8EPSS 0.022
CVE-2021-44747
Denial-of-Service (DoS) Vulnerability
Published 2022-03-01 · Modified
6.5EPSS 0.006
CVE-2021-33603
Denial-of-Service (DoS) Vulnerability
Published 2021-10-08 · Modified
6.5EPSS 0.006
CVE-2021-40832
Denial-of-Service (DoS) Vulnerability
Published 2021-10-08 · Modified
6.5EPSS 0.006
CVE-2022-28875
Denial-of-Service (DoS) Vulnerability
Published 2022-05-25 · Modified
6.5EPSS 0.005
CVE-2004-0235
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
Published 2004-05-05 · Modified
6.4EPSS 0.041
CVE-2004-2405
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.
Published 2005-08-18 · Modified
6.4EPSS 0.017
CVE-2020-9342
The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.
Published 2020-02-22 · Modified
5.5EPSS 0.016
CVE-2021-33602
Denial-of-Service (DoS) Vulnerability
Published 2021-10-06 · Modified
5.5EPSS 0.006
CVE-2022-28886
Denial-of-Service (DoS) Vulnerability
Published 2022-09-23 · Modified
5.5EPSS 0.005
CVE-2021-40836
Denial-of-Service (DoS) Vulnerability
Published 2021-12-22 · Modified
5.5EPSS 0.005
CVE-2021-40833
Denial-of-Service (DoS) Vulnerability
Published 2021-11-26 · Modified
5.5EPSS 0.004
1 / 2Next →