Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2019-12042

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.
0
Attacker Value
Unknown

CVE-2018-6322

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group.
0
Attacker Value
Unknown

CVE-2018-6321

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows local users to gain privileges via a malicious artefact.
0
Attacker Value
Unknown

CVE-2017-17683

Disclosure Date: December 14, 2017 (last updated November 26, 2024)
Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c44 \\.\PSMEMDriver DeviceIoControl request.
0
Attacker Value
Unknown

CVE-2017-17684

Disclosure Date: December 14, 2017 (last updated November 26, 2024)
Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c04 \\.\PSMEMDriver DeviceIoControl request.
0
Attacker Value
Unknown

CVE-2015-1438

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary code with kernel privileges via a crafted size input for allocated kernel paged pool and allocated non-paged pool buffers.
0
Attacker Value
Unknown

CVE-2014-5307

Disclosure Date: August 26, 2014 (last updated October 05, 2023)
Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.
0
Attacker Value
Unknown

CVE-2014-3450

Disclosure Date: May 23, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4215

Disclosure Date: December 07, 2009 (last updated October 04, 2023)
Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.
0