Vulnerabilities > K7Computing > Total Security > Low

DATE CVE VULNERABILITY TITLE RISK
2018-01-16 CVE-2017-16556 Improper Input Validation vulnerability in K7Computing products
In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations.
local
low complexity
k7computing CWE-20
2.1
2018-01-16 CVE-2017-17429 Improper Input Validation vulnerability in K7Computing products
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
local
low complexity
k7computing CWE-20
2.1
2018-01-04 CVE-2017-18019 Improper Input Validation vulnerability in K7Computing Total Security 14.2.0.252
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory.
local
low complexity
k7computing CWE-20
3.6