Vulnerabilities (CVE)

Filtered by vendor Kaspersky Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-36199 1 Kaspersky 1 Tinycheck 2021-07-21 7.5 HIGH 9.8 CRITICAL
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
CVE-2017-12816 1 Kaspersky 1 Internet Security 2021-06-17 7.5 HIGH 9.8 CRITICAL
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.
CVE-2020-35929 1 Kaspersky 1 Tinycheck 2021-01-29 5.0 MEDIUM 9.8 CRITICAL
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.
CVE-2018-6289 1 Kaspersky 1 Secure Mail Gateway 2018-02-23 10.0 HIGH 9.8 CRITICAL
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
CVE-2017-9811 1 Kaspersky 1 Anti-virus For Linux Server 2017-08-12 10.0 HIGH 9.8 CRITICAL
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the privileges to root.