Show filters
194 Total Results
Displaying 21-30 of 194
Sort by:
Attacker Value
Unknown

CVE-2019-15687

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version of the product, host unique ID). Information Disclosure.
Attacker Value
Unknown

CVE-2019-15686

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass.
Attacker Value
Unknown

CVE-2019-15685

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass.
Attacker Value
Unknown

CVE-2019-15688

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.
Attacker Value
Unknown

Implicit loading of DLLs

Disclosure Date: November 13, 2019 (last updated November 08, 2023)
A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.
Attacker Value
Unknown

CVE-2019-18654

Disclosure Date: November 01, 2019 (last updated November 08, 2023)
A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.
Attacker Value
Unknown

CVE-2019-18644

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.
Attacker Value
Unknown

CVE-2019-18645

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.
Attacker Value
Unknown

CVE-2019-17093

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that use WMI, e.g., AVGSvc.exe 19.6.4546.0 and TuneupSmartScan.dll 19.1.884.0.
Attacker Value
Unknown

CVE-2019-13355

Disclosure Date: September 24, 2019 (last updated November 27, 2024)
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hijack dotnetproxy.exe, which leads to privilege escalation when the ccSchedulerSVC service runs the executable.