Show filters
77 Total Results
Displaying 31-40 of 77
Sort by:
Attacker Value
Unknown
CVE-2020-23907
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution.
0
Attacker Value
Unknown
CVE-2021-27241
Disclosure Date: March 29, 2021 (last updated February 22, 2025)
This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Security 20.8.2429 (Build 20.8.5653.561). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AvastSvc.exe module. By creating a directory junction, an attacker can abuse the service to delete a directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12082.
0
Attacker Value
Unknown
CVE-2020-25289
Disclosure Date: September 13, 2020 (last updated February 22, 2025)
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
0
Attacker Value
Unknown
CVE-2020-15024
Disclosure Date: September 10, 2020 (last updated February 22, 2025)
An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.
0
Attacker Value
Unknown
CVE-2020-13657
Disclosure Date: June 29, 2020 (last updated November 28, 2024)
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control of arbitrary files.
0
Attacker Value
Unknown
CVE-2020-10868
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App RPC call from a Low Integrity process.
0
Attacker Value
Unknown
CVE-2020-10867
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.
0
Attacker Value
Unknown
CVE-2020-10865
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity process.
0
Attacker Value
Unknown
CVE-2020-10866
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC.
0
Attacker Value
Unknown
CVE-2020-10863
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine.
0