← Back

Kaspersky

kaspersky

62 CVEs • 29 products

Products (29)

Click to collapse
Toggle
Anti Virus
anti-virus
Tinycheck
tinycheck
Safe Browser
safe_browser
Protection
protection
Rescue Disk
rescue_disk
Security
security

CVEs (62)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kaspersky
1Security
Mar 4, 2025
Feb 29, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actio...Show more
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions.Show less
1Kaspersky
1Vpn Secure Connection
Nov 21, 2024
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
1Kaspersky
6Anti Virus
Endpoint SecurityInternet Security+3 more
Nov 21, 2024
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary c...Show more
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).Show less
1Kaspersky
6Anti Virus
Endpoint SecurityInternet Security+3 more
Nov 21, 2024
Apr 1, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted b...Show more
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRASShow less
1Kaspersky
1Password Manager
Nov 21, 2024
Nov 23, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
1Kaspersky
1Endpoint Security
Nov 21, 2024
Nov 3, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system...Show more
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.Show less
1Kaspersky
1Password Manager
Nov 21, 2024
May 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some a...Show more
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).Show less
1Kaspersky
1Internet Security
Nov 21, 2024
Apr 1, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.
1Kaspersky
2Endpoint Security
Rescue Disk
Nov 21, 2024
Feb 26, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the...Show more
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.Show less
1Kaspersky
1Tinycheck
Nov 21, 2024
Jan 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.
1Kaspersky
1Tinycheck
Nov 21, 2024
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
1Kaspersky
1Tinycheck
Nov 21, 2024
Jan 19, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access...Show more
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.Show less
1Kaspersky
1Anti Ransomware Tool
Nov 21, 2024
Dec 4, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
1Kaspersky
2Security Center
Security Center Web Console
Nov 21, 2024
Sep 2, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.
1Kaspersky
1Virus Removal Tool
Nov 21, 2024
Sep 2, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an attacker with the opportunity to eliminate content of any file in the system.
1Kaspersky
1Vpn Secure Connection
Nov 21, 2024
Sep 2, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.
1Kaspersky
4Kaspersky Internet Security
Secure ConnectionSecurity Cloud+1 more
Nov 21, 2024
Dec 2, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution comprom...Show more
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security productsShow less
1Kaspersky
5Anti Virus
Internet SecuritySecurity Cloud+2 more
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequatel...Show more
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.Show less
1Kaspersky
5Anti Virus
Internet SecuritySecurity Cloud+2 more
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to...Show more
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version of the product, host unique ID). Information Disclosure.Show less
1Kaspersky
5Anti Virus
Internet SecuritySecurity Cloud+2 more
Nov 21, 2024
Nov 26, 2019
N/A· v4
4.3 MEDIUM· v3
5.8 MEDIUM· v2
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attack...Show more
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass.Show less