Show filters
77 Total Results
Displaying 41-50 of 77
Sort by:
Attacker Value
Unknown

CVE-2020-10863

Disclosure Date: April 01, 2020 (last updated November 27, 2024)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine.
Attacker Value
Unknown

CVE-2020-10864

Disclosure Date: April 01, 2020 (last updated November 27, 2024)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a reboot via RPC from a Low Integrity process.
Attacker Value
Unknown

CVE-2020-10861

Disclosure Date: April 01, 2020 (last updated November 27, 2024)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avast Program Path via RPC, when Self Defense is Enabled.
Attacker Value
Unknown

CVE-2020-10860

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Denial of Service of the Avast Service (AvastSvc.exe).
Attacker Value
Unknown

CVE-2020-8987

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using AntiTrack with "Allow filtering of HTTPS traffic for tracking detection" enabled. (This is the default configuration.)
Attacker Value
Unknown

CVE-2020-9399

Disclosure Date: February 28, 2020 (last updated February 21, 2025)
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux.
Attacker Value
Unknown

CVE-2019-18894

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the processing of a command allows execution of arbitrary OS commands with the privileges of the currently logged in user. This allows for example attackers who compromised a browser extension to escape from the browser sandbox.
Attacker Value
Unknown

CVE-2019-18893

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.
Attacker Value
Unknown

CVE-2019-18653

Disclosure Date: November 01, 2019 (last updated November 08, 2023)
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.
Attacker Value
Unknown

CVE-2019-17093

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that use WMI, e.g., AVGSvc.exe 19.6.4546.0 and TuneupSmartScan.dll 19.1.884.0.