Vulnerabilities > Rising Global

DATE CVE VULNERABILITY TITLE RISK
2010-04-28 CVE-2010-1591 Improper Input Validation vulnerability in Rising-Global Rising Antivirus 2008/2009/2010
Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI.
local
low complexity
rising-global CWE-20
7.2
2008-12-12 CVE-2008-5539 Improper Input Validation vulnerability in Rising-Global Rising Antivirus 20.61.42.00/21.06.31.00
RISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
rising-global microsoft CWE-20
critical
9.3
2008-04-30 CVE-2008-1738 Improper Input Validation vulnerability in Rising-Global Rising Antivirus
Rising Antivirus 2008 before 20.38.20 allows local users to cause a denial of service (system crash) via an invalid pointer to the _CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.
local
low complexity
rising-global CWE-20
2.1