← Vulnerability feed

Vulnerability record · CVE-2006-2838 · published 6 June 2006

CVE-2006-2838: F-secure anti-virus vulnerability

F Secure · F Secure Anti Virus

Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.

7.6 CVSS 2.0 High EPSS 5.7% · top 7.3%
7.6CVSS 2.0 base score
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2838 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2967F-secure anti-virus improper input validation vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scann…EPSS 4.8%10.0CVE-2006-6409F-secure anti-virus vulnerabilityF-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass vir…EPSS 3.7%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2007-3300F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header …EPSS 3.7%8.8CVE-2021-33601F-secure internet gatekeeper vulnerabilityA vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web u…EPSS 0.94%7.6CVE-2008-6085F-secure anti-virus vulnerabilityInteger overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, w…EPSS 5.5%7.5CVE-2022-28887F-secure elements endpoint detection and response improper resource shutdown vulnerabilityMultiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crash…EPSS 0.40%7.5CVE-2022-28884Withsecure business suite vulnerabilityA Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2006-2838), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.