Vulnerabilities > Avast > Avast Antivirus Professional > 4.8.1351

DATE CVE VULNERABILITY TITLE RISK
2010-02-25 CVE-2010-0705 Improper Input Validation vulnerability in Avast Antivirus Home and Avast Antivirus Professional
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
local
low complexity
avast microsoft CWE-20
7.2
2009-10-01 CVE-2009-3522 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Avast Antivirus Home and Avast Antivirus Professional
Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.
local
low complexity
avast CWE-119
7.2