Show filters
194 Total Results
Displaying 31-40 of 194
Sort by:
Attacker Value
Unknown
CVE-2019-13357
Disclosure Date: September 24, 2019 (last updated November 27, 2024)
In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable.
0
Attacker Value
Unknown
CVE-2019-13356
Disclosure Date: September 24, 2019 (last updated November 27, 2024)
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, which leads to privilege escalation when the AMRT service loads the DLL.
0
Attacker Value
Unknown
CVE-2019-8286
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6
0
Attacker Value
Unknown
CVE-2018-20331
Disclosure Date: December 23, 2018 (last updated November 27, 2024)
Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002004 by the ssdt.sys kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation. A failed exploit could lead to denial of service.
0
Attacker Value
Unknown
CVE-2018-18388
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222.
0
Attacker Value
Unknown
CVE-2018-19650
Disclosure Date: December 05, 2018 (last updated November 27, 2024)
Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security management v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002000 by the IRPFile.sys Antiy-AVL ATool kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data, which results in a kernel stack buffer overflow. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation and a failed exploit could lead to denial of service.
0
Attacker Value
Unknown
SB10193 - consumer and corporate products - Maliciously misconfigured registry …
Disclosure Date: April 03, 2018 (last updated November 08, 2023)
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.
0
Attacker Value
Unknown
CVE-2018-6208
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x22000d.
0
Attacker Value
Unknown
CVE-2018-6209
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.
0
Attacker Value
Unknown
CVE-2018-6206
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220011.
0