Show filters
102 Total Results
Displaying 1-10 of 102
Sort by:
Attacker Value
Unknown

CVE-2024-13614

Disclosure Date: February 06, 2025 (last updated February 07, 2025)
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products.
0
Attacker Value
Unknown

CVE-2023-23349

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
0
Attacker Value
Unknown

CVE-2024-1619

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions.
0
Attacker Value
Unknown

CVE-2022-27535

Disclosure Date: August 05, 2022 (last updated October 08, 2023)
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
Attacker Value
Unknown

CVE-2022-27534

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
Attacker Value
Unknown

CVE-2021-27223

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS
Attacker Value
Unknown

CVE-2021-35052

Disclosure Date: November 23, 2021 (last updated October 07, 2023)
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
Attacker Value
Unknown

CVE-2021-35053

Disclosure Date: November 03, 2021 (last updated November 28, 2024)
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
Attacker Value
Unknown

CVE-2020-27020

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
Attacker Value
Unknown

CVE-2021-26718

Disclosure Date: April 01, 2021 (last updated November 28, 2024)
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.