Vulnerabilities > Panda

DATE CVE VULNERABILITY TITLE RISK
2010-02-11 CVE-2009-3735 Code Injection vulnerability in Panda Activescan 2.0
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
network
panda CWE-94
critical
9.3
2008-07-11 CVE-2008-3156 Permissions, Privileges, and Access Controls vulnerability in Panda Activescan 2.0
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.
network
panda CWE-264
critical
9.3
2008-07-11 CVE-2008-3155 Buffer Errors vulnerability in Panda Activescan 2.0
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method.
network
panda CWE-119
critical
9.3
2008-03-24 CVE-2008-1471 Resource Management Errors vulnerability in Panda products
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
local
low complexity
microsoft panda CWE-399
7.2
2007-08-08 CVE-2007-4191 Local Privilege Escalation vulnerability in Panda Antivirus 2008
Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to CVE-2006-4657.
local
panda
6.9
2007-07-25 CVE-2007-3026 Remote Integer Overflow vulnerability in Panda Adminsecure 2006
Integer overflow in Panda Software AdminSecure allows remote attackers to execute arbitrary code via crafted packets with modified length values to TCP ports 19226 or 19227, resulting in a heap-based buffer overflow.
network
panda
critical
9.3
2007-05-09 CVE-2007-1673 Resource Management Errors vulnerability in multiple products
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
7.8
2007-05-09 CVE-2007-1670 Remote Denial of Service vulnerability in Multiple Vendors Zoo Compression Algorithm
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
network
low complexity
panda
7.8
2006-11-17 CVE-2006-5967 Remote vulnerability in Panda ActiveScan ActiveX Controls
Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe.
network
high complexity
panda
5.1
2006-11-17 CVE-2006-5966 Resource Management Errors vulnerability in Panda Activescan 5.0/5.53.00
Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbitrary file existence and size via the ObtenerTamano method in the PAVPZ.SOS.1 ActiveX control.
network
low complexity
panda CWE-399
6.4