Vulnerabilities > Softwin

DATE CVE VULNERABILITY TITLE RISK
2012-03-21 CVE-2012-1429 Permissions, Privileges, and Access Controls vulnerability in multiple products
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location.
4.3
2006-12-18 CVE-2006-6627 Integer Overflow vulnerability in Multiple BitDefender Products Parsing Engine
Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the "cevakrnl.xmd vulnerability."
network
low complexity
softwin
critical
10.0
2006-12-10 CVE-2006-6405 Unspecified vulnerability in Softwin Bitdefender Mail Protection 2.0
BitDefender Mail Protection for SMB 2.0 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.
network
low complexity
softwin
5.0
2005-10-14 CVE-2005-3211 Security Bypass vulnerability in Bitdefender Antivirus
Multiple interpretation error in unspecified versions of BitDefender Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
softwin
5.1
2005-10-05 CVE-2005-3154 USE of Externally-Controlled Format String vulnerability in Softwin Bitdefender 7.2/8.0/9.0
Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.
network
low complexity
softwin CWE-134
7.5
2005-07-19 CVE-2005-2298 Security Bypass vulnerability in Bitdefender Engine
BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards.
network
low complexity
softwin
5.0
2005-05-02 CVE-2005-1286 Local Security vulnerability in Softwin Bitdefender Antivirus Professionalplus8/Standard8
Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.
local
high complexity
softwin
1.2
2004-04-19 CVE-2004-1947 Remote File Upload And Execution vulnerability in Softwin BitDefender AvxScanOnlineCtrl COM Object
The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.
network
low complexity
softwin
5.0