← Back

Bitdefender

bitdefender

106 CVEs • 34 products

Products (34)

Click to collapse
Toggle
Gravityzone
gravityzone
Antivirus
antivirus
Bitdefender
bitdefender
Engines
engines
Box Firmware
box_firmware
Safepay
safepay
Update Server
update_server
Scan Engines
scan_engines
Napoca
napoca
Central
central
Vpn Standalone
vpn_standalone
Virus Scanner
virus_scanner
Securepass
securepass
Box
box
Box 2
box_2

CVEs (106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Bitdefender
BullguardSoftware602
4Antivirus
BitdefenderGroupware Server+1 more
Apr 23, 2026
Dec 10, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers...Show more
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, possibly related to included compressed streams that were processed with the ASCIIHexDecode filter. NOTE: some of these details are obtained from third party information.Show less
1Bitdefender
1Antivirus
Apr 23, 2026
Apr 30, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
BitDefender Antivirus 2008 20080118 and earlier allows local users to cause a denial of service (system crash) via an invalid pointer to the CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descri...Show more
BitDefender Antivirus 2008 20080118 and earlier allows local users to cause a denial of service (system crash) via an invalid pointer to the CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.Show less
1Bitdefender
1Update Server
Apr 23, 2026
Jan 23, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files...Show more
Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.Show less
1Bitdefender
1Online Anti Virus Scanner
Apr 23, 2026
Nov 30, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%...Show more
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow.Show less
1Bitdefender
3Antivirus
Internet SecurityTotal Security
Apr 23, 2026
Nov 1, 2007
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable infor...Show more
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Bitdefender
1Bitdefender Client
Apr 23, 2026
Jan 19, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings.