Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Premium Security MEDIUM 6.1
CVE-2021-27241

This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Security 20.8.2429 (Build 20.8.5…

Mitigation only
Fix from $1,600 2021-03-29
Secureline Vpn MEDIUM 5.5
CVE-2020-25289

The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the l…

Fix: 5.6.4982.470+
Fix from $1,600 2020-09-13
Antivirus MEDIUM 5.5
CVE-2020-15024

An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continu…

Mitigation only
Fix from $1,600 2020-09-10
Avg Antivirus MEDIUM 5.5
CVE-2020-13657

An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The …

Fix: 20.4+
Fix from $1,600 2020-06-29
Antivirus CRITICAL 9.8
CVE-2020-10867

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $2,300 2020-04-01
Antivirus HIGH 7.5
CVE-2020-10868

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antivirus HIGH 7.5
CVE-2020-10865

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antivirus HIGH 7.5
CVE-2020-10866

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antivirus MEDIUM 6.5
CVE-2020-10864

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,600 2020-04-01
Antivirus HIGH 7.8
CVE-2020-10862

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antivirus HIGH 7.5
CVE-2020-10860

An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Deni…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antivirus HIGH 7.5
CVE-2020-10861

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antivirus HIGH 7.5
CVE-2020-10863

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows atta…

Fix: 20.0+
Fix from $1,950 2020-04-01
Antitrack HIGH 7.4
CVE-2020-8987

Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man…

Fix: 1.5.1.172 / 2.0.0.178+
Fix from $1,950 2020-03-09
Antivirus For Linux MEDIUM 5.5
CVE-2020-9399

The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antiviru…

Fix: 12.0+
Fix from $1,600 2020-02-28
Secure Browser HIGH 7.8
CVE-2019-17190

A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the Avast…

No fix yet
Fix from $1,950 2020-01-27
Premium Security HIGH 7.8
CVE-2019-18894

In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to s…

No fix yet
Fix from $1,950 2020-01-13
Secure Browser MEDIUM 6.1
CVE-2019-18893

XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute …

Fix: 1.5+
Fix from $1,600 2020-01-13
Antivirus MEDIUM 6.1
CVE-2019-18653

A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Net…

No fix yet
Fix from $1,600 2019-11-01
Antivirus HIGH 7.8
CVE-2019-17093

An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %W…

Fix: 19.8+
Fix from $1,950 2019-10-23
Free Antivirus HIGH 7.8
CVE-2018-12572

Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dum…

Fix: 19.1.2360+
Fix from $1,950 2019-03-21
Antivirus CRITICAL 9.8
CVE-2017-8307

In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries,…

Fix: after 12.3.2279
Fix from $2,300 2017-04-27
Antivirus HIGH 7.5
CVE-2017-8308

In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of th…

Fix: after 12.3.2279
Fix from $1,950 2017-04-27
Free Antivirus MEDIUM 6.7
CVE-2017-5567

Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free An…

Fix: after 12.3
Fix from $1,600 2017-03-21
Business Security MEDIUM 5.5
CVE-2016-4025

Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.…

Fix: after 8.0.1609
Fix from $1,600 2016-11-03
Avast Free Antivirus HIGH 7.8
CVE-2015-8620

Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus bef…

Fix: after 11.1.2245
Fix from $1,950 2016-04-13
Avast HIGH 7.8
CVE-2016-3986EPSS 8%

Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to …

No fix yet
Fix from $1,950 2016-04-12
Avast Antivirus MEDIUM 6.4
CVE-2015-5662

Directory traversal vulnerability in Avast before 150918-0 allows remote attackers to delete or write to arbitrary files via a crafted entry in a ZIP…

Fix: after 151017-1
Fix from $1,600 2015-10-18
Avast Antivirus Free HIGH 9.3
CVE-2010-3126EPSS 8%

Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execut…

Fix: after 5.0.594
Fix from $1,950 2010-08-26
Avast Antivirus Home HIGH 7.2
CVE-2010-0705

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d…

Fix: after 5.0.396.0
Fix from $1,950 2010-02-25