MidnightBSD

Advisories for norman

CVE-2005-3220 MEDIUM

Multiple interpretation error in unspecified versions of Norman Virus Control Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
norman virus_control_antivirus *
CVE-2005-3378 MEDIUM

Multiple interpretation error in Norman 5.81 with the 5.83.02 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
norman norman_virus_control 5.81_engine_5.83.02
CVE-2010-5167 MEDIUM

Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
norman security_suite 8.0
CVE-2012-1420 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
cat quick_heal 11.00
fortinet fortinet_antivirus 4.2.254.0
rising-global rising_antivirus 22.83.00.03
authentium command_antivirus 5.2.11.5
kaspersky kaspersky_anti-virus 7.0.0.125
k7computing antivirus 9.77.3565
f-prot f-prot_antivirus 4.6.2.117
microsoft security_essentials 2.0
norman norman_antivirus_&_antispyware 6.06.12
eset nod32_antivirus 5795
CVE-2012-1421 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1422 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial ITSF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
norman norman_antivirus_&_antispyware 6.06.12
eset nod32_antivirus 5795
CVE-2012-1423 MEDIUM

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
virusbuster virusbuster 13.6.151.0
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pc_tools pc_tools_antivirus 7.0.3.5
rising-global rising_antivirus 22.83.00.03
authentium command_antivirus 5.2.11.5
k7computing antivirus 9.77.3565
f-prot f-prot_antivirus 4.6.2.117
norman norman_antivirus_&_antispyware 6.06.12
emsisoft anti-malware 5.1.0.1
eset nod32_antivirus 5795
CVE-2012-1424 MEDIUM

The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
jiangmin jiangmin_antivirus 13.0.900
pc_tools pc_tools_antivirus 7.0.3.5
sophos sophos_anti-virus 4.61.0
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
CVE-2012-1425 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee scan_engine 5.400.0.1158
avira antivir 7.11.1.163
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
mcafee gateway 2010.1c
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
jiangmin jiangmin_antivirus 13.0.900
pc_tools pc_tools_antivirus 7.0.3.5
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
CVE-2012-1426 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
authentium command_antivirus 5.2.11.5
k7computing antivirus 9.77.3565
f-prot f-prot_antivirus 4.6.2.117
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1427 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1428 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1440 MEDIUM

The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified identsize field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
fortinet fortinet_antivirus 4.2.254.0
ca etrust_vet_antivirus 36.1.8511
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
gdata-software g_data_antivirus 21
f-secure f-secure_anti-virus 9.0.16160.0
ahnlab v3_internet_security 2011.01.18.00
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
aladdin esafe 7.0.17.0
avg avg_anti-virus 10.0.0.1190
mcafee gateway 2010.1c
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pc_tools pc_tools_antivirus 7.0.3.5
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 5.0.677.0
nprotect nprotect_antivirus 2011-01-17.01
symantec endpoint_protection 11.0
f-prot f-prot_antivirus 4.6.2.117
microsoft security_essentials 2.0
anti-virus vba32 3.12.14.2
bitdefender bitdefender 7.2
avira antivir 7.11.1.163
kaspersky kaspersky_anti-virus 7.0.0.125
clamav clamav 0.96.4
k7computing antivirus 9.77.3565
sophos sophos_anti-virus 4.61.0
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
virusbuster virusbuster 13.6.151.0
jiangmin jiangmin_antivirus 13.0.900
comodo comodo_antivirus 7424
authentium command_antivirus 5.2.11.5
alwil avast_antivirus 4.8.1351.0
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
CVE-2012-1446 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
ca etrust_vet_antivirus 36.1.8511
kaspersky kaspersky_anti-virus 7.0.0.125
sophos sophos_anti-virus 4.61.0
aladdin esafe 7.0.17.0
mcafee gateway 2010.1c
fortinet fortinet_antivirus 4.2.254.0
pc_tools pc_tools_antivirus 7.0.3.5
rising-global rising_antivirus 22.83.00.03
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
CVE-2012-1456 MEDIUM

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
sophos sophos_anti-virus 4.61.0
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
aladdin esafe 7.0.17.0
avg avg_anti-virus 10.0.0.1190
mcafee gateway 2010.1c
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
jiangmin jiangmin_antivirus 13.0.900
comodo comodo_antivirus 7424
rising-global rising_antivirus 22.83.00.03
symantec endpoint_protection 11.0
f-prot f-prot_antivirus 4.6.2.117
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
gdata-software g_data_antivirus 21
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
aladdin esafe 7.0.17.0
avg avg_anti-virus 10.0.0.1190
mcafee gateway 2010.1c
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pc_tools pc_tools_antivirus 7.0.3.5
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 5.0.677.0
symantec endpoint_protection 11.0
f-prot f-prot_antivirus 4.6.2.117
microsoft security_essentials 2.0
anti-virus vba32 3.12.14.2
bitdefender bitdefender 7.2
avira antivir 7.11.1.163
kaspersky kaspersky_anti-virus 7.0.0.125
clamav clamav 0.96.4
k7computing antivirus 9.77.3565
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
virusbuster virusbuster 13.6.151.0
jiangmin jiangmin_antivirus 13.0.900
authentium command_antivirus 5.2.11.5
alwil avast_antivirus 4.8.1351.0
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
gdata-software g_data_antivirus 21
f-secure f-secure_anti-virus 9.0.16160.0
ahnlab v3_internet_security 2011.01.18.00
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
avg avg_anti-virus 10.0.0.1190
mcafee gateway 2010.1c
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pc_tools pc_tools_antivirus 7.0.3.5
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 5.0.677.0
nprotect nprotect_antivirus 2011-01-17.01
symantec endpoint_protection 11.0
f-prot f-prot_antivirus 4.6.2.117
microsoft security_essentials 2.0
anti-virus vba32 3.12.14.2
bitdefender bitdefender 7.2
avira antivir 7.11.1.163
kaspersky kaspersky_anti-virus 7.0.0.125
clamav clamav 0.96.4
k7computing antivirus 9.77.3565
sophos sophos_anti-virus 4.61.0
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
virusbuster virusbuster 13.6.151.0
jiangmin jiangmin_antivirus 13.0.900
comodo comodo_antivirus 7424
authentium command_antivirus 5.2.11.5
alwil avast_antivirus 4.8.1351.0
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
CVE-2012-1461 MEDIUM

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee scan_engine 5.400.0.1158
bitdefender bitdefender 7.2
kaspersky kaspersky_anti-virus 7.0.0.125
f-secure f-secure_anti-virus 9.0.16160.0
k7computing antivirus 9.77.3565
sophos sophos_anti-virus 4.61.0
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
avg avg_anti-virus 10.0.0.1190
mcafee gateway 2010.1c
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
jiangmin jiangmin_antivirus 13.0.900
rising-global rising_antivirus 22.83.00.03
authentium command_antivirus 5.2.11.5
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
anti-virus vba32 3.12.14.2
CVE-2012-1463 MEDIUM

The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
mcafee scan_engine 5.400.0.1158
bitdefender bitdefender 7.2
cat quick_heal 11.00
f-secure f-secure_anti-virus 9.0.16160.0
ahnlab v3_internet_security 2011.01.18.00
aladdin esafe 7.0.17.0
comodo comodo_antivirus 7424
authentium command_antivirus 5.2.11.5
nprotect nprotect_antivirus 2011-01-17.01
f-prot f-prot_antivirus 4.6.2.117
norman norman_antivirus_&_antispyware 6.06.12
CVE-2014-0816 HIGH

Unspecified vulnerability in Norman Security Suite 10.1 and earlier allows local users to gain privileges via unknown vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
norman security_suite 8.0
norman security_suite 10.0
norman security_suite *
CVE-2020-8508 HIGH

nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
norman malware_cleaner 2.08.08