Vulnerabilities > Kaspersky > Kaspersky Internet Security

DATE CVE VULNERABILITY TITLE RISK
2019-12-02 CVE-2019-15689 Exposure of Resource to Wrong Sphere vulnerability in Kaspersky products
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights.
local
low complexity
kaspersky CWE-668
4.6
2014-09-09 CVE-2014-5654 Cryptographic Issues vulnerability in Kaspersky Internet Security 11.4.4.232
The Kaspersky Internet Security (aka com.kms.free) application 11.4.4.232 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
5.4
2009-08-25 CVE-2009-2966 Resource Management Errors vulnerability in Kaspersky Anti-Virus and Kaspersky Internet Security
avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.
network
kaspersky CWE-399
4.3
2009-07-30 CVE-2009-2647 Unspecified vulnerability in Kaspersky Anti-Virus and Kaspersky Internet Security
Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to "an external script."
network
low complexity
kaspersky
5.0
2006-06-19 CVE-2006-3074 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Kaspersky Anti-Virus and Kaspersky Internet Security
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.
network
low complexity
kaspersky microsoft CWE-119
5.0