Skip to content
Noroxi

Bitdefender records

107 published records for vendor bitdefender.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
21
With a fix record
2.8%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

107 records
  • The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8

    MediumCVSS 4.3No exploitEPSS 100%

    ahnlab · v3 internet securityMar 21, 2012

  • The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010

    MediumCVSS 4.3No exploitEPSS 100%

    cat · quick healMar 21, 2012

  • Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024.

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    bitdefender · antivirusNov 1, 2007

  • The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.

    MediumCVSS 4.3No exploitEPSS 98%

    anti-virus · vba32Mar 21, 2012

  • The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E

    MediumCVSS 4.3No exploitEPSS 96%

    bitdefender · bitdefenderMar 21, 2012

  • The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec

    MediumCVSS 4.3No exploitEPSS 96%

    bitdefender · bitdefenderMar 21, 2012

  • The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5

    MediumCVSS 4.3No exploitEPSS 94%

    ahnlab · v3 internet securityMar 21, 2012

  • The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant

    MediumCVSS 4.3No exploitEPSS 92%

    anti-virus · vba32Mar 21, 2012

  • Improper Access Control vulnerability in the patchesUpdate API

    CriticalCVSS 10.0No exploitEPSS 3%

    bitdefender · endpoint security toolsNov 24, 2021

  • Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Securit

    CriticalCVSS 9.3Proof of conceptEPSS 11%

    bitdefender · antivirusDec 10, 2008

  • The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which al

    CriticalCVSS 9.8No exploitEPSS 4%

    bitdefender · gravityzoneOct 24, 2018

  • Bitdefender BOX 2 bootstrap download_image command injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 4%

    bitdefender · box 2 firmwareJan 27, 2020

  • Bitdefender BOX 2 bootstrap get_image_size command injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    bitdefender · box 2 firmwareJan 27, 2020

  • CVE-2014-5350
    39Monitor

    Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via

    MediumCVSS 5.0Proof of conceptEPSS 64%

    bitdefender · gravityzoneAug 19, 2014

  • CVE-2007-6189
    39Monitor

    A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to exec

    CriticalCVSS 9.3Proof of conceptEPSS 8%

    bitdefender · online anti-virus scannerNov 29, 2007

  • CVE-2017-8931
    39Monitor

    Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.

    CriticalCVSS 9.8No exploitEPSS 2%

    bitdefender · gravityzoneOct 30, 2018

  • CVE-2021-3823
    39Monitor

    Path traversal vulnerability in Bitdefender GravitZone Update Server in relay mode

    CriticalCVSS 9.8No exploitEPSS 1%

    bitdefender · gravityzoneOct 28, 2021

  • CVE-2022-2830
    39Monitor

    Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)

    CriticalCVSS 9.8No exploitEPSS 1%

    bitdefender · gravityzoneSep 5, 2022

  • CVE-2024-2224
    39Monitor

    Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)

    CriticalCVSS 9.8No exploitEPSS 1%

    bitdefender · endpoint securityApr 9, 2024

  • CVE-2024-2223
    39Monitor

    Incorrect Regular Expression in GravityZone Update Server (VA-11465)

    CriticalCVSS 9.8No exploitEPSS 1%

    bitdefender · endpoint securityApr 9, 2024

  • CVE-2024-4177
    39Monitor

    Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)

    CriticalCVSS 9.8No exploitEPSS 0%

    bitdefender · gravityzoneJun 6, 2024

  • CVE-2025-2244
    38Monitor

    Insecure PHP deserialization issue in GravityZone Console (VA-12634)

    CriticalCVSS 9.5No exploitEPSS 1%

    bitdefender · gravityzoneApr 4, 2025

  • This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018.

    HighCVSS 8.8No exploitEPSS 6%

    bitdefender · internet security 2018Dec 21, 2017

  • Unauthenticated Command Injection in Bitdefender BOX v1

    CriticalCVSS 9.4No exploitEPSS 1%

    bitdefender · box firmwareMar 12, 2025

  • CVE-2025-1987
    37Monitor

    Stored XSS in Psono-Client via Malicious Vault Entry URLs

    CriticalCVSS 9.3No exploitEPSS 1%

    esaqa · psono clientJun 21, 2025