Vulnerabilities > Pandasecurity > Panda Antivirus
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-12-07 | CVE-2009-4215 | Permissions, Privileges, and Access Controls vulnerability in Pandasecurity products Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs. | 7.2 |
2008-12-12 | CVE-2008-5536 | Improper Input Validation vulnerability in Pandasecurity Panda Antivirus 9.0.0.4 Panda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. | 9.3 |