Show filters
595 Total Results
Displaying 151-160 of 595
Sort by:
Attacker Value
Unknown

CVE-2020-13657

Disclosure Date: June 29, 2020 (last updated November 28, 2024)
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control of arbitrary files.
Attacker Value
Unknown

CVE-2020-14955

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220440.
Attacker Value
Unknown

CVE-2020-3350

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
Attacker Value
Unknown

CVE-2020-8103

Disclosure Date: June 05, 2020 (last updated February 21, 2025)
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdefender Antivirus Free versions prior to 1.0.17.178.
Attacker Value
Unknown

CVE-2020-3327

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
Attacker Value
Unknown

CVE-2020-3341

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
Attacker Value
Unknown

CVE-2020-12680

Disclosure Date: May 08, 2020 (last updated November 08, 2023)
Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collecting credentials stored in Chrome, Firefox, Opera, and Edge. The executable does not verify the calling program and thus a request such as fetchChromePasswords or fetchCredentials will succeed. NOTE: some third parties have stated that this is "not a vulnerability.
Attacker Value
Unknown

CVE-2020-11446

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
Attacker Value
Unknown

CVE-2020-12254

Disclosure Date: April 26, 2020 (last updated February 21, 2025)
Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.
Attacker Value
Unknown

CVE-2020-8099

Disclosure Date: April 21, 2020 (last updated February 21, 2025)
A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects: Bitdefender Antivirus Free versions prior to 1.0.17.