Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security HIGH 8.8
CVE-2024-1619

Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an a…

Fix: after 8.0.3.30
Fix from $1,950 2024-02-29
Vpn Secure Connection HIGH 7.8
CVE-2022-27535

Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data An…

Fix: 21.6+
Fix from $1,950 2022-08-05
Anti Virus CRITICAL 9.8
CVE-2022-27534

Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data par…

Fix: 12.03.2022+
Fix from $2,300 2022-04-01
Anti Virus MEDIUM 5.5
CVE-2021-27223

A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. …

Fix: 2021-06+
Fix from $1,600 2022-04-01
Password Manager HIGH 7.8
CVE-2021-35052

A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.

Fix: after 9.0.1
Fix from $1,950 2021-11-23
Endpoint Security HIGH 7.5
CVE-2021-35053

Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser paramet…

Fix: after 11.6.0
Fix from $1,950 2021-11-03
Password Manager HIGH 7.5
CVE-2020-27020

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict g…

Fix: 9.2 / 9.2.14.31+
Fix from $1,950 2021-05-14
Internet Security MEDIUM 5.5
CVE-2021-26718

KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

Fix: 21.1+
Fix from $1,600 2021-04-01
Endpoint Security MEDIUM 6.8
CVE-2020-26200

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component…

Fix: 18.0.11.3+
Fix from $1,600 2021-02-26
Tinycheck CRITICAL 9.8
CVE-2020-36199

TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.

Fix: 2020-12-18+
Fix from $2,300 2021-01-26
Tinycheck MEDIUM 6.5
CVE-2020-36200

TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.

Fix: 2020-12-18+
Fix from $1,600 2021-01-26
Tinycheck CRITICAL 9.8
CVE-2020-35929

In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool…

Fix: 2020-12-18+
Fix from $2,300 2021-01-19
Anti Ransomware Tool HIGH 7.8
CVE-2020-28950

The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to…

Fix: 4.0+
Fix from $1,950 2020-12-04
Security Center HIGH 7.8
CVE-2020-25045

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijackin…

Fix: 12+
Fix from $1,950 2020-09-02
Vpn Secure Connection HIGH 7.1
CVE-2020-25043

The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any fi…

Fix: 5.0+
Fix from $1,950 2020-09-02
Virus Removal Tool HIGH 7.1
CVE-2020-25044

Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an attacker with the opportunit…

Fix: 15.0.23.0+
Fix from $1,950 2020-09-02
Kaspersky Internet Security MEDIUM 6.7
CVE-2019-15689

Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug t…

No fix yet
Fix from $1,600 2019-12-02
Anti Virus MEDIUM 6.5
CVE-2019-15687

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Se…

Fix: after 2020
Fix from $1,600 2019-11-26
Anti Virus MEDIUM 6.1
CVE-2019-15688

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Se…

Fix: after 2020
Fix from $1,600 2019-11-26
Antivirus Engine HIGH 8.8
CVE-2019-8285

Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execut…

Fix: 2019.04.04+
Fix from $1,950 2019-05-08
Password Manager HIGH 7.8
CVE-2018-6306

Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.

Fix: 8.0.6.538+
Fix from $1,950 2018-04-19
Secure Mail Gateway CRITICAL 9.8
CVE-2018-6289EPSS 7%

Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.

No fix yet
Fix from $2,300 2018-02-06
Secure Mail Gateway HIGH 8.8
CVE-2018-6288

Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.

No fix yet
Fix from $1,950 2018-02-06
Secure Mail Gateway HIGH 7.8
CVE-2018-6290

Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.

No fix yet
Fix from $1,950 2018-02-06
Secure Mail Gateway MEDIUM 6.1
CVE-2018-6291

WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.

No fix yet
Fix from $1,600 2018-02-06
Embedded Systems Security HIGH 7.8
CVE-2017-12823

Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.

Mitigation only
Fix from $1,950 2017-12-08
Internet Security CRITICAL 9.8
CVE-2017-12816

In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malwa…

Mitigation only
Fix from $2,300 2017-08-25
Internet Security HIGH 7.5
CVE-2017-12817

In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.

Mitigation only
Fix from $1,950 2017-08-25
Anti Virus For Linux Server CRITICAL 9.8
CVE-2017-9811EPSS 10%

The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 …

Fix: after 8.0.3.297
Fix from $2,300 2017-07-17
Anti Virus For Linux Server HIGH 8.8
CVE-2017-9810

There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix …

Fix: after 8.0.3.297
Fix from $1,950 2017-07-17