Show filters
185 Total Results
Displaying 21-30 of 185
Sort by:
Attacker Value
Unknown
CVE-2023-42520
Disclosure Date: September 18, 2023 (last updated October 08, 2023)
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.
0
Attacker Value
Unknown
CVE-2022-25631
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated
0
Attacker Value
Unknown
CVE-2022-37017
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.
0
Attacker Value
Unknown
CVE-2022-37016
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
0
Attacker Value
Unknown
CVE-2022-38166
Disclosure Date: November 25, 2022 (last updated October 08, 2023)
In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service.
0
Attacker Value
Unknown
CVE-2022-28887
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
0
Attacker Value
Unknown
CVE-2022-28886
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine
0
Attacker Value
Unknown
CVE-2022-28884
Disclosure Date: September 06, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
0
Attacker Value
Unknown
CVE-2022-28883
Disclosure Date: August 23, 2022 (last updated October 08, 2023)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker.
0
Attacker Value
Unknown
CVE-2022-28882
Disclosure Date: August 23, 2022 (last updated October 08, 2023)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker.
0