Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7.1) | 1.2% | 💥 Exploit | K7computing Total Security | 4/1/2018 | 17/6/2026 | In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a… | |
| Modificada | Alta (7) | 0.34% | — | Bitdefender Total Security | 29/8/2017 | 17/6/2026 | This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of… | |
| Modificada | Alta (7.8) | 2.0% | 💥 Exploit | 360totalsecurity 360 Total Security | 7/8/2017 | 17/6/2026 | 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory. | |
| Modificada | Alta (7.5) | 0.93% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection mechanisms that provide sufficient defense against directed attacks against the product. | |
| Modificada | Crítica (9.8) | 1.2% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. | |
| Modificada | Crítica (9.8) | 2.3% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote… | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Quickheal Total Security | 20/4/2017 | 17/6/2026 | The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service. | |
| Modificada | Media (6.7) | 0.94% | — | Avira Free Security SuiteAvira Internet Security SuiteAvira Optimization SuiteAvira Total Security Suite | 21/3/2017 | 17/6/2026 | Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (and earlier), and Free Security Suite 15.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any… | |
| Modificada | Media (6.7) | 0.75% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 21/3/2017 | 17/6/2026 | Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack.… | |
| Modificada | Media (5.5) | 0.57% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Total Security | 6/1/2017 | 17/6/2026 | A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism. | |
| Modificada | Media (5.5) | 0.66% | — | Kaspersky Total Security | 6/1/2017 | 17/6/2026 | Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in… | |
| Modificada | Crítica (9.8) | 9.7% | 💥 PoC | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 2/1/2017 | 17/6/2026 | Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security… | |
| Modificada | Media (6.4) | 1.5% | — | Kaspersky Total Security 2015 | 16/12/2015 | 17/6/2026 | Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.0% | 💥 Exploit | K7computing K7sentry.sysK7computing Anti-virus PlusK7computing Total SecurityK7computing Ultimate Security | 6/2/2015 | 17/6/2026 | K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call. | |
| Modificada | Media (6.2) | 0.30% | — | Bitdefender Total Security 2010 | 25/8/2012 | 16/6/2026 | Race condition in BitDefender Total Security 2010 13.0.20.347 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Alta (7.2) | 0.70% | 💥 Exploit | Quickheal Antivirus Plus 2009Quickheal Total Security 2009 | 4/1/2010 | 16/6/2026 | Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe. |