Vulnerabilities > Avira > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-07-27 CVE-2016-10402 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Avira Antivirus 5.0.2003.1821/8.3.36.59
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.
network
avira CWE-119
critical
9.3
2015-09-21 CVE-2015-7303 Unspecified vulnerability in Avira Management Console
Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header.
network
low complexity
avira
critical
10.0
2007-06-01 CVE-2007-2974 Remote vulnerability in Avira Antivir Antivirus
Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an "integer cast around."
network
low complexity
avira
critical
10.0