📦

kaspersky_anti-virus

Vendor: kaspersky

Actively Exploited 0 CISA KEV List
PoC / Exploits 15 Code Available
Total RCEs 1 Remote Access
Total CVEs 43 Total Indexed
Avg. EPSS 30.47% Exploit Prob.
Latest CVE CVE-2012-1462 Mar 21

Security Vulnerability Index

Page 4 / 5
5.1 CVSS

Multiple interpretation error in unspecified versions of Kaspersky Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

EPSS: 1.72%
10.0 CVSS

Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header.

EPSS: 42.54%
3.6 CVSS

Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary files via a symlink attack on kavmonitor.log, or delete license keys and prevent keepup2date from properly executing.

EPSS: 0.42%
7.2 CVSS
CVE-2005-1905
Exploit Found

The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.

EPSS: 0.73%
7.5 CVSS
CVE-2004-0937
Exploit Found

Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 14.79%
7.5 CVSS
CVE-2004-0933
Exploit Found

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 20.69%
7.5 CVSS
CVE-2004-0936
Exploit Found

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 14.79%
7.5 CVSS
CVE-2004-0935
Exploit Found

Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 15.06%
7.5 CVSS
CVE-2004-0932
Exploit Found

McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 65.76%
7.5 CVSS
CVE-2004-0934
Exploit Found

Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 14.79%