Show filters
315 Total Results
Displaying 11-20 of 315
Sort by:
Attacker Value
Unknown

CVE-2024-0353

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
Attacker Value
Unknown

CVE-2023-7043

Disclosure Date: January 31, 2024 (last updated February 09, 2024)
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
Attacker Value
Unknown

CVE-2024-23940

Disclosure Date: January 29, 2024 (last updated February 07, 2024)
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.
Attacker Value
Unknown

CVE-2023-5594

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
Attacker Value
Unknown

CVE-2023-3160

Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
Attacker Value
Unknown

CVE-2023-28929

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file is started.
Attacker Value
Unknown

CVE-2022-0357

Disclosure Date: May 24, 2023 (last updated October 08, 2023)
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45.
Attacker Value
Unknown

CVE-2022-28887

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
Attacker Value
Unknown

CVE-2022-28886

Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine
Attacker Value
Unknown

CVE-2022-28884

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.