Skip to main content

Vendor archive

avast CVEs

Beta · best-effort

75 CVEs tagged to vendor avast8 Critical, 40 High, 26 Medium, 1 Low, 0 Unrated.

CVE-2019-18653

Published Nov 1, 2019

A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allow…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17093

Published Oct 23, 2019

An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll,…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-11230

Published Jul 18, 2019

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the p…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12572

Published Mar 21, 2019

Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8308

Published Apr 27, 2017

In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8307

Published Apr 27, 2017

In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4025

Published Nov 3, 2016

Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8…

CVSS 5.5 · Medium

CVE-2016-3986

Published Apr 12, 2016

Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5662

Published Oct 18, 2015

Directory traversal vulnerability in Avast before 150918-0 allows remote attackers to delete or write to arbitrary files via a crafted entry in a ZIP archive.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0122

Published Apr 22, 2013

The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3126

Published Aug 26, 2010

Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct D…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6846

Published Jul 2, 2009

Multiple stack-based buffer overflows in avast! Linux Home Edition 1.0.5, 1.0.5-1, and 1.0.8 allow remote attackers to cause a denial of service (application crash) or execute arb…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2845

Published May 24, 2007

Heap-based buffer overflow in the CAB unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted CAB…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1673

Published May 9, 2007

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry st…

CVSS 7.8 · High

CVE-2007-1672

Published May 9, 2007

avast! antivirus before 4.7.981 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 75 CVEsPage 3 of 3