← Back

Acer

acer

53 CVEs • 116 products

Products (116)

Click to collapse
Toggle
Care Center
care_center
Acer Portal
acer_portal
Quick Access
quick_access
Quickaccess
quickaccess
Chromebase
chromebase
Chromebase 24
chromebase_24
Chromebox
chromebox
Altos T110 F3
altos_t110_f3
Ap130 F2
ap130_f2
Aspire 1600x
aspire_1600x
Aspire 1602m
aspire_1602m
Aspire 7600u
aspire_7600u
Aspire Mc605
aspire_mc605
Aspire Tc 105
aspire_tc-105
Aspire Tc 120
aspire_tc-120
Aspire U5 620
aspire_u5-620
Aspire X1935
aspire_x1935
Aspire X3475
aspire_x3475
Aspire X3995
aspire_x3995
Aspire Xc100
aspire_xc100
Aspire Xc600
aspire_xc600
Aspire Z3 615
aspire_z3-615
Veriton E430g
veriton_e430g
Veriton E430
veriton_e430
Veriton M2611
veriton_m2611
Veriton M4620
veriton_m4620

CVEs (53)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Acer
1Care Center
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority called ACCsvc through a named pipe. In this case, the Name...Show more
Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority called ACCsvc through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general user. In addition, the service program does not verify the user when communicating. A thread may exist with a specific command. When the path of the program to be executed is sent, there is a local privilege escalation in which the service program executes the path with system privileges.Show less
1Acer
1Care Center
Jun 17, 2026
Jan 26, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect h...Show more
In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with local administrator privileges.Show less
1Acer
1Quick Access
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, whi...Show more
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, which is running as NT AUTHORITY\SYSTEM. This is a DLL Hijacking vulnerability (including search order hijacking, which searches for the missing DLL in the PATH environment variable), which is caused by an uncontrolled search path element for nvapi.dll, atiadlxx.dll, or atiadlxy.dll.Show less
1Acer
1Acer Portal
May 13, 2026
Jun 8, 2017
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.
3Acer
GoogleSamsung
6Ac700 Chromebook
Chrome OsChromebox 3+3 more
Apr 29, 2026
Jun 7, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Feb 29, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Jan 12, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Dec 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
1Acer
1Lunchapp.aplunch
Apr 23, 2026
Aug 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006...Show more
Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006-6121.Show less
1Acer
1Lunchapp.aplunch
Apr 23, 2026
Nov 26, 2006
N/A· v4
N/A· v3
9.3 HIGH· v2
Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.