Show filters
102 Total Results
Displaying 31-40 of 102
Sort by:
Attacker Value
Unknown
CVE-2018-6288
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown
CVE-2017-12823
Disclosure Date: December 08, 2017 (last updated November 26, 2024)
Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.
0
Attacker Value
Unknown
CVE-2017-12817
Disclosure Date: August 25, 2017 (last updated November 26, 2024)
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
0
Attacker Value
Unknown
CVE-2017-12816
Disclosure Date: August 25, 2017 (last updated November 26, 2024)
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.
0
Attacker Value
Unknown
CVE-2017-9813
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptName parameter of the licenseKeyInfo action method is vulnerable to cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2017-9812
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.
0
Attacker Value
Unknown
CVE-2017-9810
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
0
Attacker Value
Unknown
CVE-2017-9811
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the privileges to root.
0
Attacker Value
Unknown
CVE-2016-4304
Disclosure Date: January 06, 2017 (last updated November 25, 2024)
A denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF driver. A specially crafted native api call request can cause a access violation exception in KLIF kernel driver resulting in local denial of service. An attacker can run program from user-mode to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2016-4329
Disclosure Date: January 06, 2017 (last updated November 25, 2024)
A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism.
0