Vulnerabilities > Panda > Panda Activescan

DATE CVE VULNERABILITY TITLE RISK
2010-02-11 CVE-2009-3735 Code Injection vulnerability in Panda Activescan 2.0
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
network
panda CWE-94
critical
9.3
2008-07-11 CVE-2008-3156 Permissions, Privileges, and Access Controls vulnerability in Panda Activescan 2.0
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.
network
panda CWE-264
critical
9.3
2008-07-11 CVE-2008-3155 Buffer Errors vulnerability in Panda Activescan 2.0
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method.
network
panda CWE-119
critical
9.3
2007-05-09 CVE-2007-1670 Remote Denial of Service vulnerability in Multiple Vendors Zoo Compression Algorithm
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
network
low complexity
panda
7.8
2006-08-23 CVE-2006-4295 Cross-Site Scripting vulnerability in Panda Activescan 5.53.00
Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
network
panda
4.3
2005-11-30 CVE-2005-3922 Heap Overflow vulnerability in Panda Software Antivirus Library ZOO Archive
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.
network
low complexity
panda
7.5