CVE Feed

    Dashboard / CVE / CVE-2010-1425

    CVE-2010-1425

    F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security 8 and earlier, and for E-mail and Server security 9 and earlier; Mac Protection build 8060 and earlier; Client Security 9 and earlier; and various Anti-Virus products for Windows, Linux, and Citrix; does not properly detect malware in crafted (1) 7Z, (2) GZIP, (3) CAB, or (4) RAR archives, which makes it easier for remote attackers to avoid detection.

    Published:Apr 15, 2010
    Last Modified:Apr 11, 2025
    EPS:Apr 15, 2010
    EPSS Score:0.00499
    CVSS Score:5

    Affected Products

    Vendor
    F-secure
    Product
    Anti-virus
    Vendor
    F-secure
    Product
    F-secure Anti-virus
    Vendor
    F-secure
    Product
    F-secure Anti-virus Client Security
    Vendor
    F-secure
    Product
    F-secure Anti-virus For Citrix Servers
    Vendor
    F-secure
    Product
    F-secure Anti-virus For Linux
    Vendor
    F-secure
    Product
    F-secure Anti-virus For Microsoft Exchange
    Vendor
    F-secure
    Product
    F-secure Anti-virus For Mimesweeper
    Vendor
    F-secure
    Product
    F-secure Anti-virus For Windows Servers
    Vendor
    F-secure
    Product
    F-secure Anti-virus For Workstations
    Vendor
    F-secure
    Product
    F-secure Anti-virus Linux Client Security
    Vendor
    F-secure
    Product
    F-secure Anti-virus Linux Server Security
    Vendor
    F-secure
    Product
    F-secure Internet Security
    Vendor
    F-secure
    Product
    Home Server Security
    Vendor
    F-secure
    Product
    Internet Gatekeeper

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High