MidnightBSD

Advisories for avg

CVE-2006-6618 HIGH

AntiHook 3.0.0.23 - Desktop relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avg antivirus_plus_firewall 7.5.431
infoprocess antihook 3.0.23
symantec sygate_personal_firewall 5.6.2808
soft4ever look_n_stop 2.05p2
filseclab personal_firewall 3.0.8686
comodo comodo_personal_firewall 2.3.6.81
CVE-2006-6619 HIGH

AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avg antivirus_plus_firewall 7.5.431
infoprocess antihook 3.0.23
symantec sygate_personal_firewall 5.6.2808
filseclab personal_firewall 3.0.8686
soft4ever look_n_stop 2.05p2
comodo comodo_personal_firewall 2.3.6.81
CVE-2006-6620 HIGH

Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avg antivirus_plus_firewall 7.5.431
infoprocess antihook 3.0.23
symantec sygate_personal_firewall 5.6.2808
soft4ever look_n_stop 2.05p2
filseclab personal_firewall 3.0.8686
comodo comodo_personal_firewall 2.3.6.81
CVE-2006-6621 HIGH

Filseclab Personal Firewall 3.0.0.8686 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avg antivirus_plus_firewall 7.5.431
infoprocess antihook 3.0.23
symantec sygate_personal_firewall 5.6.2808
soft4ever look_n_stop 2.05p2
filseclab personal_firewall 3.0.8686
comodo comodo_personal_firewall 2.3.6.81
CVE-2006-6622 HIGH

Soft4Ever Look 'n' Stop (LnS) 2.05p2 before 20061215 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avg antivirus_plus_firewall 7.5.431
infoprocess antihook 3.0.23
symantec sygate_personal_firewall 5.6.2808
soft4ever look_n_stop 2.05p2
filseclab personal_firewall 3.0.8686
comodo comodo_personal_firewall 2.3.6.81
CVE-2006-6623 HIGH

Sygate Personal Firewall 5.6.2808 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avg antivirus_plus_firewall 7.5.431
infoprocess antihook 3.0.23
symantec sygate_personal_firewall 5.6.2808
filseclab personal_firewall 3.0.8686
soft4ever look_n_stop 2.05p2
comodo comodo_personal_firewall 2.3.6.81
CVE-2008-5522 HIGH

AVG Anti-Virus 8.0.0.161, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
avg antivirus 8.0.0.161
CVE-2008-5530 HIGH

Ewido Security Suite 4.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
avg ewido_security_suite 4.0
ewido ewido_security_suite 4.0
CVE-2008-6662 MEDIUM

AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
avg avg_anti-virus 7.5.51
CVE-2009-1784 HIGH

The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
avg avg_anti-virus 7.5.448
avg avg_anti-virus 7.0
avg avg_anti-virus 7.0.251
avg avg_anti-virus 7.5.476
avg avg_anti-virus *
avg avg_anti-virus 7.0.323
avg avg_anti-virus 7.5.51
avg avg_anti-virus 7.1.308
avg avg_anti-virus 7.1.407
avg avg_anti-virus 6.0.710
avg avg_anti-virus 8.0
CVE-2010-3498 MEDIUM

AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg anti-virus *
CVE-2010-5152 MEDIUM

Race condition in AVG Internet Security 9.0.791 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
avg internet_security 9.0.791
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg avg_anti-virus 10.0.0.1190
k7computing antivirus 9.77.3565
ahnlab v3_internet_security 2011.01.18.00
comodo comodo_antivirus 7424
fortinet fortinet_antivirus 4.2.254.0
norman norman_antivirus_&_antispyware 6.06.12
clamav clamav 0.96.4
anti-virus vba32 3.12.14.2
eset nod32_antivirus 5795
jiangmin jiangmin_antivirus 13.0.900
avira antivir 7.11.1.163
aladdin esafe 7.0.17.0
f-secure f-secure_anti-virus 9.0.16160.0
pc_tools pc_tools_antivirus 7.0.3.5
emsisoft anti-malware 5.1.0.1
alwil avast_antivirus 5.0.677.0
pandasecurity panda_antivirus 10.0.2.7
f-prot f-prot_antivirus 4.6.2.117
gdata-software g_data_antivirus 21
antiy avl_sdk 2.0.3.7
symantec endpoint_protection 11.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
mcafee scan_engine 5.400.0.1158
alwil avast_antivirus 4.8.1351.0
sophos sophos_anti-virus 4.61.0
virusbuster virusbuster 13.6.151.0
bitdefender bitdefender 7.2
kaspersky kaspersky_anti-virus 7.0.0.125
microsoft security_essentials 2.0
mcafee gateway 2010.1c
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
authentium command_antivirus 5.2.11.5
nprotect nprotect_antivirus 2011-01-17.01
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
CVE-2012-1456 MEDIUM

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg avg_anti-virus 10.0.0.1190
comodo comodo_antivirus 7424
fortinet fortinet_antivirus 4.2.254.0
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
jiangmin jiangmin_antivirus 13.0.900
aladdin esafe 7.0.17.0
sophos sophos_anti-virus 4.61.0
emsisoft anti-malware 5.1.0.1
kaspersky kaspersky_anti-virus 7.0.0.125
mcafee gateway 2010.1c
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
f-prot f-prot_antivirus 4.6.2.117
pandasecurity panda_antivirus 10.0.2.7
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg avg_anti-virus 10.0.0.1190
k7computing antivirus 9.77.3565
norman norman_antivirus_&_antispyware 6.06.12
clamav clamav 0.96.4
anti-virus vba32 3.12.14.2
jiangmin jiangmin_antivirus 13.0.900
eset nod32_antivirus 5795
avira antivir 7.11.1.163
aladdin esafe 7.0.17.0
pc_tools pc_tools_antivirus 7.0.3.5
emsisoft anti-malware 5.1.0.1
alwil avast_antivirus 5.0.677.0
gdata-software g_data_antivirus 21
f-prot f-prot_antivirus 4.6.2.117
antiy avl_sdk 2.0.3.7
symantec endpoint_protection 11.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
mcafee scan_engine 5.400.0.1158
alwil avast_antivirus 4.8.1351.0
virusbuster virusbuster 13.6.151.0
bitdefender bitdefender 7.2
microsoft security_essentials 2.0
kaspersky kaspersky_anti-virus 7.0.0.125
mcafee gateway 2010.1c
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
authentium command_antivirus 5.2.11.5
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
k7computing antivirus 9.77.3565
ahnlab v3_internet_security 2011.01.18.00
avg avg_anti-virus 10.0.0.1190
comodo comodo_antivirus 7424
fortinet fortinet_antivirus 4.2.254.0
norman norman_antivirus_&_antispyware 6.06.12
clamav clamav 0.96.4
anti-virus vba32 3.12.14.2
jiangmin jiangmin_antivirus 13.0.900
eset nod32_antivirus 5795
avira antivir 7.11.1.163
f-secure f-secure_anti-virus 9.0.16160.0
pc_tools pc_tools_antivirus 7.0.3.5
emsisoft anti-malware 5.1.0.1
alwil avast_antivirus 5.0.677.0
pandasecurity panda_antivirus 10.0.2.7
f-prot f-prot_antivirus 4.6.2.117
gdata-software g_data_antivirus 21
antiy avl_sdk 2.0.3.7
symantec endpoint_protection 11.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
mcafee scan_engine 5.400.0.1158
alwil avast_antivirus 4.8.1351.0
virusbuster virusbuster 13.6.151.0
sophos sophos_anti-virus 4.61.0
bitdefender bitdefender 7.2
microsoft security_essentials 2.0
kaspersky kaspersky_anti-virus 7.0.0.125
mcafee gateway 2010.1c
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
authentium command_antivirus 5.2.11.5
nprotect nprotect_antivirus 2011-01-17.01
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
CVE-2012-1461 MEDIUM

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg avg_anti-virus 10.0.0.1190
k7computing antivirus 9.77.3565
fortinet fortinet_antivirus 4.2.254.0
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
anti-virus vba32 3.12.14.2
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
jiangmin jiangmin_antivirus 13.0.900
f-secure f-secure_anti-virus 9.0.16160.0
sophos sophos_anti-virus 4.61.0
bitdefender bitdefender 7.2
kaspersky kaspersky_anti-virus 7.0.0.125
emsisoft anti-malware 5.1.0.1
mcafee gateway 2010.1c
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
authentium command_antivirus 5.2.11.5
rising-global rising_antivirus 22.83.00.03
CVE-2012-1462 MEDIUM

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg avg_anti-virus 10.0.0.1190
ahnlab v3_internet_security 2011.01.18.00
fortinet fortinet_antivirus 4.2.254.0
symantec endpoint_protection 11.0
emsisoft anti-malware 5.1.0.1
kaspersky kaspersky_anti-virus 7.0.0.125
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
jiangmin jiangmin_antivirus 13.0.900
aladdin esafe 7.0.17.0
cat quick_heal 11.00
CVE-2012-6335 LOW

The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
avg avg_antivirus -
CVE-2014-2956 HIGH

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg safeguard *
avg secure_search_toolbar *
CVE-2014-9632 HIGH

The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg internet_security *
avg protection *
CVE-2015-8578 MEDIUM

AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avg internet_security 2015
CVE-2017-5566 HIGH

Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any AVG process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-427,

Products Affected

Vendor Product Version
avg ultimate 17.1
avg internet_security 17.1
avg anti-virus 17.1
CVE-2017-9977 MEDIUM

AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
avg anti-virus -