CVE-2025-69875
- EPSS 0.01%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 16:06:40
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into prot...
CVE-2024-48292
- EPSS 0.16%
- Veröffentlicht 18.11.2024 18:15:06
- Zuletzt bearbeitet 19.11.2024 21:57:56
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.
- EPSS 0.04%
- Veröffentlicht 23.05.2022 19:16:07
- Zuletzt bearbeitet 21.11.2024 07:04:30
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time ...
CVE-2022-31467
- EPSS 0.07%
- Veröffentlicht 23.05.2022 19:16:07
- Zuletzt bearbeitet 21.11.2024 07:04:30
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for req...
CVE-2020-27585
- EPSS 0.04%
- Veröffentlicht 30.11.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:21:24
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
CVE-2020-27586
- EPSS 0.15%
- Veröffentlicht 30.11.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:21:25
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
CVE-2020-27587
- EPSS 0.05%
- Veröffentlicht 30.11.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:21:25
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
CVE-2020-9362
- EPSS 0.21%
- Veröffentlicht 24.02.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:40:29
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, A...
CVE-2018-8090
- EPSS 0.44%
- Veröffentlicht 25.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:14
Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) -...
CVE-2017-8773
- EPSS 2.4%
- Veröffentlicht 04.05.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMH...