Show filters
194 Total Results
Displaying 121-130 of 194
Sort by:
Attacker Value
Unknown

CVE-2007-4787

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
0
Attacker Value
Unknown

CVE-2007-4512

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted filename that is not properly handled by the print function in SavMain.exe.
0
Attacker Value
Unknown

CVE-2007-4649

Disclosure Date: August 31, 2007 (last updated October 04, 2023)
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
0
Attacker Value
Unknown

CVE-2007-4578

Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.
0
Attacker Value
Unknown

CVE-2007-4577

Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
0
Attacker Value
Unknown

CVE-2007-3875

Disclosure Date: July 26, 2007 (last updated October 04, 2023)
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
0
Attacker Value
Unknown

CVE-2007-3906

Disclosure Date: July 19, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Kaspersky Anti-Virus for Check Point FireWall-1 before Critical Fix 1 (5.5.161.0) might allow attackers to cause a denial of service (kernel hang) via unspecified vectors. NOTE: it is not clear whether there is an attacker role.
0
Attacker Value
Unknown

CVE-2007-3825

Disclosure Date: July 18, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certain data to unspecified RPC procedures.
0
Attacker Value
Unknown

CVE-2007-3300

Disclosure Date: June 20, 2007 (last updated October 04, 2023)
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
0
Attacker Value
Unknown

CVE-2007-2863

Disclosure Date: June 06, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file.
0