Safe
Vendor:
First CVE: May 17, 2019 · Active for 7 years
19
Total CVEs
More Total CVEs than 93% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Safe over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2019
7 years ago
Most Recent CVE
Dec 23, 2022
1,309 days ago
CVE Severity & Scoring
Safe19 CVEs
16%
58%
21%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None3 (15.8%)
Unknown0 (0.0%)
Required16 (84.2%)
Privileges Required
Low4 (21.1%)
High0 (0.0%)
None15 (78.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44749CRITICAL A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection | Mar 6, 2022 | 9.6 | 30 | NO | NO |
CVE-2022-28872HIGH A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not corr | May 12, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-14977HIGH An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and c | Jun 23, 2020 | 8.1 | 26 | NO | NO |
CVE-2019-11644HIGH In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and P | May 17, 2019 | 7.8 | 25 | NO | NO |
CVE-2022-38164MEDIUM A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only | Nov 7, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-44748MEDIUM A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute th | Mar 6, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-14978HIGH An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged co | Jun 23, 2020 | 8.1 | 21 | NO | NO |
CVE-2022-47524MEDIUM F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack. | Dec 23, 2022 | 5.4 | 19 | NO | NO |
CVE-2021-44751MEDIUM A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F- | Mar 25, 2022 | 5.3 | 19 | NO | NO |
CVE-2022-28873MEDIUM A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address ba | May 12, 2022 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Safe
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 18.5 | 2 | 7.8 | 0.7% | 0 | 0 |
| 17.7 | 2 | 8.1 | 3.0% | 0 | 0 |