Vulnerabilities (CVE)

Filtered by vendor Avast Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-23907 1 Avast 1 Retdec 2021-04-26 7.5 HIGH 9.8 CRITICAL
An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution.
CVE-2020-10867 2 Avast, Microsoft 2 Antivirus, Windows 2020-04-02 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.
CVE-2017-8307 1 Avast 1 Antivirus 2019-10-03 7.5 HIGH 9.8 CRITICAL
In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary files. This vulnerability is exploitable by any unprivileged user when Avast Self-Defense is disabled. It is also exploitable in conjunction with CVE-2017-8308 when Avast Self-Defense is enabled. The vulnerability allows for Denial of Service attacks and hiding traces of a possible attack.