VendorsF-Securesafeall versions
Vulnerabilities

F-Secure Safe 17.6 for Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2021-44749
Universal Cross-Site Scripting Vulnerability in F-Secure SAFE Browser Protection for Android
Published 2022-03-06 · Modified
9.6EPSS 0.008
CVE-2020-14978
An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.
Published 2020-06-23 · Modified
9.3EPSS 0.031
CVE-2020-14977
An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.
Published 2020-06-23 · Modified
9.3EPSS 0.028
CVE-2022-28872
Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Published 2022-05-12 · Modified
8.8EPSS 0.005
CVE-2019-11644
In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer Protection Standard and Premium before 19.3, a local user can escalate their privileges through a DLL hijacking attack against the installer. The installer writes the file rm.exe to C:\Windows\Temp and then executes it. The rm.exe process then attempts to load several DLLs from its current directory. Non-admin users are able to write to this folder, so an attacker can create a malicious C:\Windows\Temp\OLEACC.dll file. When an admin runs the installer, rm.exe will execute the attacker's DLL in an elevated security context.
Published 2019-05-17 · Modified
7.8EPSS 0.015
CVE-2022-38164
A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL.
Published 2022-11-07 · Modified
6.5EPSS 0.005
CVE-2021-44748
Universal Cross-Site Scripting Vulnerability in F-Secure SAFE Browser for Android
Published 2022-03-06 · Modified
6.1EPSS 0.005
CVE-2022-47524
F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.
Published 2022-12-23 · Modified
5.4EPSS 0.004
CVE-2021-44751
F-Secure SAFE Browser vulnerable to USSD attacks
Published 2022-03-25 · Modified
5.3EPSS 0.006
CVE-2021-40835
URL Address Bar Spoofing in F-Secure SAFE Browser for iOS
Published 2021-12-16 · Modified
4.6EPSS 0.007
CVE-2021-40834
User interface Spoofing in F-Secure SAFE browser for Android
Published 2021-12-10 · Modified
4.3EPSS 0.007
CVE-2022-28873
Multiple Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Published 2022-05-12 · Modified
4.3EPSS 0.006
CVE-2022-28868
Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Published 2022-04-15 · Modified
4.3EPSS 0.005
CVE-2022-28870
Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Published 2022-04-15 · Modified
4.3EPSS 0.005
CVE-2022-28869
Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android
Published 2022-04-15 · Modified
4.3EPSS 0.005
CVE-2021-33596
Fake Apple login prompt in F-Secure SAFE browser for iOS
Published 2021-08-05 · Modified
4.1EPSS 0.008
CVE-2021-33595
F-Secure Safe browser for iOS vulnerable to Address Bar Spoofing
Published 2021-08-11 · Modified
3.5EPSS 0.011
CVE-2021-33594
F-Secure Safe browser for Android vulnerable to Address Bar Spoofing
Published 2021-08-11 · Modified
3.5EPSS 0.011
CVE-2022-38163
A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below. Drag and drop operation by user on address bar could lead to a spoofing of the address bar.
Published 2022-11-07 · Modified
3.5EPSS 0.006