5 results (0.012 seconds)

CVSS: 5.0EPSS: 31%CPEs: 2EXPL: 3

FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file. NOTE: this issue has at least a partial overlap with CVE-2006-6294. FRISK Software F-Prot Antivirus anterior a 4.6.7 permite a atacantes remotos con la intervención del usuario provocar una denegación de servicio (bucle infinito) mediante un fichero ACE artesanal. NOTA: este asunto está parcialmente solapado con CVE-2006-6294. • https://www.exploit-db.com/exploits/2892 http://gleg.net/fprot.txt http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051096.html http://secunia.com/advisories/23328 http://security.gentoo.org/glsa/glsa-200612-12.xml http://securityreason.com/securityalert/1998 http://securitytracker.com/id?1017331 http://www.f-prot.com/news/gen_news/061201_release_unix467.html http://www.securityfocus.com/archive/1/453475/100/0/threaded http://www.securityfocus.com/bid/214 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Multiple unspecified vulnerabilities in FRISK Software F-Prot Antivirus before 4.6.7 have unspecified impact and attack vectors. NOTE: this might be related to CVE-2006-6293, but it is not clear due to the vagueness of the report. Múltiples vulnerabilidades no especificadas en FRISK Software F-Prot Antivirus anterior a 4.6.7 tienen impacto y vectores de ataque desconocidos. NOTA: esto puede estar relacionado con CVE-2006-6293, pero no esta claro debido a la vaguedad del informe. • http://secunia.com/advisories/23328 http://security.gentoo.org/glsa/glsa-200612-12.xml http://www.f-prot.com/news/gen_news/061201_release_unix467.html •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the file. • http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0073.html http://securitytracker.com/id?1015148 http://thierry.sniff-em.com/research/fprot.html http://www.osvdb.org/20865 http://www.securityfocus.com/archive/1/415637/30/0/threaded http://www.securityfocus.com/archive/1/502370/100/0/threaded http://www.securityfocus.com/bid/15293 http://www.zoller.lu/research/fprot.htm https://exchange.xforce.ibmcloud.com/vulnerabilities/22967 •

CVSS: 5.1EPSS: 0%CPEs: 1EXPL: 0

Multiple interpretation error in F-Prot 3.16c allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug." • http://marc.info/?l=bugtraq&m=113026417802703&w=2 http://www.securityelf.org/magicbyte.html http://www.securityelf.org/magicbyteadv.html http://www.securityelf.org/updmagic.html http://www.securityfocus.com/bid/15189 •

CVSS: 5.1EPSS: 0%CPEs: 1EXPL: 0

Multiple interpretation error in unspecified versions of F-Prot Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper. • http://marc.info/?l=bugtraq&m=112879611919750&w=2 http://shadock.net/secubox/AVCraftedArchive.html •