Known vulnerabilities in Kaspersky Anti-Virus
Vendor:
Kaspersky Lab
Software:
Kaspersky Anti-Virus
Software CPE:
cpe:2.3:a:kaspersky_lab:kaspersky_anti-virus:*:*:*:*:*:*:*:*
Total vulnerabilities:
7
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
21.20.8.505
21.19.7.533
21.17.7.539
21.18.5.438
21.16.6.467
21.15.8.493
21.14.5.462
21.13.5.506
21.9.6.465
21.3.10.391k
11.7.0.669
21.3.10.391j
21.3.10.391i
21.3.10.391h
21.3.10.391g
21.3.10.391f
21.3.10.391e
21.3.10.391d
21.3.10.391c
21.3.10.391b
21.3.10.391a
21.3.10.391
21.2.16.590c
21.2.16.590b
21.2.16.590a
21.2.16.590
21.1.15.500c
21.1.15.500b
21.1.15.500a
21.1.15.500
11.8.0.384
11.6.0.394
11.5.0.590
12.03.2022
21.3.10.391(c)
21.3.10.391(g)
8.0.4.312
8.0
7.0.0.125
9.0.0.463
2010
5.0.712
6.0.3.837
7.0.1.325
2008
7.0
5.5.10
6.0
5.5.3
5.0.372
5.0.5
5.0.227
5.0.228
5.0.335
4.0
5.0
3.0
4.0.9.0
3.5.132.2
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU62699 - Improper Control of Generation of Code ('Code Injection') CVE-2022-27534 |
CWE-94 | Medium | 12.03.2022 | 29.04.2022 |
SB2022042908 |
||
| #VU62698 - Improper input validation CVE-2021-27223 |
CWE-20 | Low | 21.3.10.391(c) | 29.04.2022 |
SB2022042907 |
||
| #VU61045 - Improper Link Resolution Before File Access ('Link Following') CVE-2021-35053 |
CWE-59 | Low | 21.3.10.391(g) | 07.03.2022 |
SB2022030705 |
||
| #VU7236 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2017-9812 |
CWE-22 | Low | - | 29.06.2017 |
SB2017062904 |
||
| #VU7235 - Command injection CVE-2017-9811 |
CWE-77 | Low | - | 29.06.2017 |
SB2017062904 |
||
| #VU7234 - Cross-Site Request Forgery (CSRF) CVE-2017-9813 |
CWE-352 | Low | - | 29.06.2017 |
SB2017062904 |
||
| #VU7233 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2017-9810 |
CWE-79 | Low | - | 29.06.2017 |
SB2017062904 |