Frisk Software's vulnerability profile centers on its F-PROT antivirus product, a niche but historically significant endpoint-protection solution. The limited disclosed vulnerabilities associate with the product's scanning and signature-handling mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frisk Software over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6352MEDIUM FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file. NOTE: this issue has at lea | Dec 7, 2006 | 5.0 | 27 | NO | YES |
CVE-2005-3499HIGH Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the | Nov 4, 2005 | 7.5 | 20 | NO | NO |
CVE-2006-6294HIGH Multiple unspecified vulnerabilities in FRISK Software F-Prot Antivirus before 4.6.7 have unspecified impact and attack vectors. NOTE: this might be related to CVE-2006-6293, but i | Dec 5, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-3374MEDIUM Multiple interpretation error in F-Prot 3.16c allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is norma | Oct 30, 2005 | 5.1 | 15 | NO | NO |
CVE-2005-3213MEDIUM Multiple interpretation error in unspecified versions of F-Prot Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR fi | Oct 14, 2005 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frisk Software.
Media articles that mention a CVE ID that affects a product developed by Frisk Software — matched by CVE ID, not by vendor name.