Skip to main content

Vendor archive

avira CVEs

Beta · best-effort

41 CVEs tagged to vendor avira3 Critical, 22 High, 16 Medium, 0 Low, 0 Unrated.

CVE-2026-27750

Published Mar 5, 2026

Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for c…

CVSS 7.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-27749

Published Mar 5, 2026

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which ru…

CVSS 7.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-27748

Published Mar 5, 2026

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM del…

CVSS 7.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2023-51636

Published May 22, 2024

Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36673

Published Aug 9, 2023

An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP ad…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1900

Published Apr 19, 2023

A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4429

Published Jan 10, 2023

Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service. The issue was fixed with Avi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3368

Published Oct 17, 2022

A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in cert…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28795

Published Apr 12, 2022

A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerabi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12680

Published May 8, 2020

Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collec…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12463

Published May 5, 2020

An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take cont…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12254

Published Apr 26, 2020

Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8961

Published Apr 9, 2020

An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injecti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9320

Published Feb 20, 2020

Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small B…

CVSS 5.5 · Medium

CVE-2019-17449

Published Oct 10, 2019

Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-10402

Published Jul 27, 2017

Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7303

Published Sep 21, 2015

Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5576

Published Sep 9, 2014

The Avira Secure Backup (aka com.avira.avirabackup) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2