Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.77%—Kaspersky Internet SecurityKaspersky Secure ConnectionKaspersky Security CloudKaspersky Total Security2/12/201917/6/2026
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible…
ModificadaMedia (5.4)0.34%—Kaspersky Internet Security9/9/201417/6/2026
The Kaspersky Internet Security (aka com.kms.free) application 11.4.4.232 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.2)0.32%—Kaspersky Internet Security 201025/8/201216/6/2026
Race condition in Kaspersky Internet Security 2010 9.0.0.736 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.8)0.82%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus 2009Kaspersky LAB Kaspersky Anti-virus 2010Kaspersky LAB Kaspersky Anti-virus Personal+329/12/200916/6/2026
Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to…
ModificadaMedia (4.3)6.4%—Kaspersky Anti-virusKaspersky Internet Security25/8/200916/6/2026
avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.
ModificadaMedia (5)2.5%—Kaspersky Anti-virusKaspersky Internet Security30/7/200916/6/2026
Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to "an external script."
ModificadaMedia (4.3)1.2%—Kaspersky LAB Kaspersky Internet Security Suite11/12/200816/6/2026
Kaspersky Internet Security Suite 2009 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a…
ModificadaAlta (7.2)0.37%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security5/6/200816/6/2026
Stack-based buffer overflow in kl1.sys in Kaspersky Anti-Virus 6.0 and 7.0 and Internet Security 6.0 and 7.0 allows local users to gain privileges via an IOCTL 0x800520e8 call.
ModificadaBaja (2.1)0.44%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security26/9/200716/6/2026
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4)…
ModificadaMedia (4.4)0.32%—Kaspersky LAB Kaspersky Internet Security24/9/200716/6/2026
Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service…
ModificadaAlta (9.3)3.3%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command. NOTE: this issue…
ModificadaAlta (10)4.9%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2)…
ModificadaMedia (6.8)0.67%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows local users to gain Ring-0 privileges via unspecified vectors.
ModificadaMedia (6.6)0.42%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument,"…
ModificadaAlta (10)8.9%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.
ModificadaAlta (7.2)1.3%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus PersonalKaspersky LAB Kaspersky Anti-virus Personal PROKaspersky LAB Kaspersky Internet Security20/10/200616/6/2026
The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary code via crafted Irp structure with invalid addresses in the…
ModificadaMedia (5)7.2%—Kaspersky Anti-virusKaspersky Internet Security19/6/200616/6/2026
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject,…