Show filters
194 Total Results
Displaying 41-50 of 194
Sort by:
Attacker Value
Unknown

CVE-2018-6202

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.
0
Attacker Value
Unknown

CVE-2018-6203

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C.
0
Attacker Value
Unknown

CVE-2018-6204

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.
0
Attacker Value
Unknown

CVE-2018-6205

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220009.
0
Attacker Value
Unknown

CVE-2018-6207

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.
0
Attacker Value
Unknown

CVE-2018-6201

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.
0
Attacker Value
Unknown

CVE-2017-9813

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptName parameter of the licenseKeyInfo action method is vulnerable to cross-site scripting (XSS).
0
Attacker Value
Unknown

CVE-2017-9812

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.
0
Attacker Value
Unknown

CVE-2017-9810

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
0
Attacker Value
Unknown

CVE-2017-9811

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the privileges to root.
0