Vulnerabilities > Gdata

DATE CVE VULNERABILITY TITLE RISK
2009-01-28 CVE-2008-6000 Resource Management Errors vulnerability in Gdata products
The GDTdiIcpt.sys driver in G DATA AntiVirus 2008, InternetSecurity 2008, and TotalCare 2008 populates kernel registers with IOCTL 0x8317001c input values, which allows local users to cause a denial of service (system crash) or gain privileges via a crafted IOCTL request, as demonstrated by execution of the KeSetEvent function with modified register contents.
local
low complexity
gdata CWE-399
7.2
2007-10-13 CVE-2007-5436 Buffer Errors vulnerability in Gdata Antivirus 2007
Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function.
network
high complexity
gdata CWE-119
7.6
2007-09-24 CVE-2007-5041 Improper Input Validation vulnerability in Gdata Internetsecurity 2007
G DATA InternetSecurity 2007 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey and (2) NtOpenProcess kernel SSDT hooks.
local
low complexity
gdata CWE-20
4.6