10

CVE-2010-5185

The Antivirus component in Comodo Internet Security before 5.3.174622.1216 does not check whether X.509 certificates in signed executable files have been revoked, which has unknown impact and remote attack vectors.

Data is provided by the National Vulnerability Database (NVD)
ComodoComodo Internet Security Version <= 5.0.163652.1142
ComodoComodo Internet Security Version3.0.14.276
ComodoComodo Internet Security Version3.0.15.277
ComodoComodo Internet Security Version3.0.16.295
ComodoComodo Internet Security Version3.0.17.304
ComodoComodo Internet Security Version3.0.18.309
ComodoComodo Internet Security Version3.0.19.318
ComodoComodo Internet Security Version3.0.20.320
ComodoComodo Internet Security Version3.0.22.349
ComodoComodo Internet Security Version3.0.23.364
ComodoComodo Internet Security Version3.0.24.368
ComodoComodo Internet Security Version3.0.25.378
ComodoComodo Internet Security Version3.5.53896.424
ComodoComodo Internet Security Version3.5.54375.427
ComodoComodo Internet Security Version3.5.55810.432
ComodoComodo Internet Security Version3.5.57173.439
ComodoComodo Internet Security Version3.8.64263.468
ComodoComodo Internet Security Version3.8.64739.471
ComodoComodo Internet Security Version3.8.65951.477
ComodoComodo Internet Security Version3.9.95478.509
ComodoComodo Internet Security Version3.10.102363.531
ComodoComodo Internet Security Version3.11.108364.552
ComodoComodo Internet Security Version3.12.111745.560
ComodoComodo Internet Security Version3.13.121240.574
ComodoComodo Internet Security Version3.13.125662.579
ComodoComodo Internet Security Version3.14.130099.587
ComodoComodo Internet Security Version4.0.138377.779
ComodoComodo Internet Security Version4.0.141842.828
ComodoComodo Internet Security Version4.1.150349.920
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.397
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.