CVE-2009-4452
- EPSS 0.16%
- Published 29.12.2009 20:41:20
- Last modified 09.04.2025 00:30:58
Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:F...
CVE-2008-1518
- EPSS 0.09%
- Published 05.06.2008 20:32:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in kl1.sys in Kaspersky Anti-Virus 6.0 and 7.0 and Internet Security 6.0 and 7.0 allows local users to gain privileges via an IOCTL 0x800520e8 call.
CVE-2007-5086
- EPSS 0.06%
- Published 26.09.2007 10:17:00
- Last modified 09.04.2025 00:30:58
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via ...
CVE-2007-5043
- EPSS 0.06%
- Published 24.09.2007 00:17:00
- Last modified 09.04.2025 00:30:58
Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the Nt...
- EPSS 19.69%
- Published 06.04.2007 00:19:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote atta...
- EPSS 3.91%
- Published 06.04.2007 00:19:00
- Last modified 09.04.2025 00:30:58
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arb...
CVE-2007-1879
- EPSS 1.77%
- Published 06.04.2007 00:19:00
- Last modified 09.04.2025 00:30:58
The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anon...
CVE-2007-1880
- EPSS 0.07%
- Published 06.04.2007 00:19:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers t...
CVE-2007-1881
- EPSS 0.13%
- Published 06.04.2007 00:19:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows local users to gain Ring-0 privileges v...
CVE-2006-4926
- EPSS 0.31%
- Published 20.10.2006 22:07:00
- Last modified 09.04.2025 00:30:58
The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary...