Skip to main content

Vendor archive

avg CVEs

Beta · best-effort

40 CVEs tagged to vendor avg4 Critical, 13 High, 22 Medium, 1 Low, 0 Unrated.

CVE-2024-7237

Published Nov 22, 2024

AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AV…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7236

Published Nov 22, 2024

AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected in…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7235

Published Nov 22, 2024

AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of A…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7234

Published Nov 22, 2024

AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AV…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9484

Published Oct 4, 2024

An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application du…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9483

Published Oct 4, 2024

A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9482

Published Oct 4, 2024

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application dur…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9481

Published Oct 4, 2024

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18654

Published Nov 1, 2019

A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to exe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17093

Published Oct 23, 2019

An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll,…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-9977

Published Jul 12, 2017

AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5566

Published Mar 21, 2017

Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) allows a local attacker to byp…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-8578

Published Dec 16, 2015

AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to byp…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9632

Published Feb 6, 2015

The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2956

Published Jul 8, 2014

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement d…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6335

Published Dec 31, 2012

The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-5152

Published Aug 25, 2012

Race condition in AVG Internet Security 9.0.791 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3498

Published Aug 22, 2012

AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitr…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1462

Published Mar 21, 2012

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0,…

CVSS 4.3 · Medium
Showing 1-25 of 40 CVEsPage 1 of 2