Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2017-8773
Disclosure Date: May 04, 2017 (last updated November 26, 2024)
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote Code Execution as well as Privilege Escalation.
0
Attacker Value
Unknown
CVE-2015-8285
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
0
Attacker Value
Unknown
CVE-2017-5005
Disclosure Date: January 02, 2017 (last updated November 25, 2024)
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
0
Attacker Value
Unknown
CVE-2013-6767
Disclosure Date: December 20, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denial of service (process crash) via a long *.text value in a PE file.
0
Attacker Value
Unknown
CVE-2009-4556
Disclosure Date: January 04, 2010 (last updated October 04, 2023)
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.
0
Attacker Value
Unknown
CVE-2008-5524
Disclosure Date: December 12, 2008 (last updated October 04, 2023)
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
0