Vulnerabilities > Avast > Avast Antivirus Home > 4.8.1335

DATE CVE VULNERABILITY TITLE RISK
2010-02-25 CVE-2010-0705 Improper Input Validation vulnerability in Avast Antivirus Home and Avast Antivirus Professional
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
local
low complexity
avast microsoft CWE-20
7.2
2009-10-01 CVE-2009-3524 Unspecified vulnerability in Avast Antivirus Home and Avast Antivirus Professional
Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.
local
low complexity
avast
7.2
2009-10-01 CVE-2009-3523 Improper Input Validation vulnerability in Avast Antivirus Home and Avast Antivirus Professional
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.
local
avast CWE-20
6.9