Show filters
99 Total Results
Displaying 71-80 of 99
Sort by:
Attacker Value
Unknown
CVE-2017-16552
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.
0
Attacker Value
Unknown
CVE-2017-17429
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
0
Attacker Value
Unknown
CVE-2017-16554
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.
0
Attacker Value
Unknown
CVE-2017-16551
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way.
0
Attacker Value
Unknown
CVE-2017-16555
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way.
0
Attacker Value
Unknown
CVE-2017-16553
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way.
0
Attacker Value
Unknown
CVE-2017-16550
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.
0
Attacker Value
Unknown
CVE-2017-18019
Disclosure Date: January 04, 2018 (last updated November 26, 2024)
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call with an invalid kernel pointer.
0
Attacker Value
Unknown
CVE-2017-10950
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of the 0x8000E038 IOCTL in the bdfwfpf driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker could leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4776.
0
Attacker Value
Unknown
CVE-2017-12653
Disclosure Date: August 07, 2017 (last updated November 26, 2024)
360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.
0