Comodo records
91 published records for vendor comodo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 30
- With a fix record
- 1.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')30
- CWE-264 Permissions, Privileges, and Access Controls11
- CWE-59 Improper Link Resolution Before File Access ('Link Following')5
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')4
- CWE-310 Cryptographic Issues3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
The weakness classes this vendor ships most often: where to look.
CWEAll records
91 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2018-17431Proof of concept | Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.comodo · unified threat management firewall · CWE-287 | Critical9.8 | — | 83.9% | Jan 30, 2019 |
47Plan | CVE-2012-1456No exploit | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Medium4.3 | — | 99.9% | Mar 21, 2012 |
47Plan | CVE-2012-1459No exploit | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 99.8% | Mar 21, 2012 |
47Plan | CVE-2012-1443No exploit | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Medium4.3 | — | 99.6% | Mar 21, 2012 |
46Plan | CVE-2012-1430No exploit | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
46Plan | CVE-2012-1431No exploit | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
46Plan | CVE-2008-0470Proof of concept | A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.comodo · comodo antivirus | Critical9.3 | — | 30.9% | Jan 29, 2008 |
45Plan | CVE-2012-1463No exploit | The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 94.2% | Mar 21, 2012 |
45Plan | CVE-2012-1429No exploit | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.comodo · comodo antivirus · CWE-264 | Medium4.3 | — | 92.5% | Mar 21, 2012 |
40Plan | CVE-2011-5121No exploit | The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not properly check whether unspecified X.509 certificates arcomodo · comodo internet security · CWE-310 | Critical10.0 | — | 1.2% | Aug 25, 2012 |
40Plan | CVE-2010-5185No exploit | The Antivirus component in Comodo Internet Security before 5.3.174622.1216 does not check whether X.509 certificates in signed executable ficomodo · comodo internet security · CWE-20 | Critical10.0 | — | 1.2% | Aug 25, 2012 |
40Plan | CVE-2011-5123No exploit | The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not check whether X.509 certificates in signed executable ficomodo · comodo internet security · CWE-310 | Critical10.0 | — | 1.2% | Aug 25, 2012 |
33Monitor | CVE-2025-7097No exploit | Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injectioncomodo · internet security · CWE-77 | High8.2 | — | 4.2% | Jul 6, 2025 |
32Monitor | CVE-2014-9633Proof of concept | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggerscomodo · backup · CWE-264 | High7.5 | — | 8.1% | Feb 3, 2015 |
32Monitor | CVE-2025-7096No exploit | Comodo Internet Security Premium Manifest File cis_update_x64.xml integrity checkcomodo · internet security · CWE-345 | High8.2 | — | 0.5% | Jul 6, 2025 |
31Monitor | CVE-2019-18215No exploit | An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0.comodo · comodo internet security · CWE-427 | High7.8 | — | 0.6% | Nov 18, 2019 |
31Monitor | CVE-2019-3969No exploit | Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Local Privilege Escalation due to CmdAgent's handling of COM clients.comodo · antivirus | High7.8 | — | 0.6% | Jul 17, 2019 |
31Monitor | CVE-2022-34008No exploit | Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation.comodo · antivirus · CWE-59 | High7.8 | — | 0.5% | Jun 21, 2022 |
31Monitor | CVE-2024-7248No exploit | Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerabilitycomodo · internet security · CWE-22 | High7.8 | — | 0.5% | Jul 29, 2024 |
31Monitor | CVE-2024-7251No exploit | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerabilitycomodo · internet security · CWE-59 | High7.8 | — | 0.3% | Jul 29, 2024 |
31Monitor | CVE-2024-7250No exploit | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerabilitycomodo · internet security · CWE-59 | High7.8 | — | 0.3% | Jul 29, 2024 |
31Monitor | CVE-2024-7252No exploit | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerabilitycomodo · internet security · CWE-59 | High7.8 | — | 0.3% | Jul 29, 2024 |
31Monitor | CVE-2024-7249No exploit | Comodo Firewall Link Following Local Privilege Escalation Vulnerabilitycomodo · firewall · CWE-59 | High7.8 | — | 0.3% | Jul 29, 2024 |
28Monitor | CVE-2014-7872Proof of concept | Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to thcomodo · geekbuddy · CWE-264 | High7.2 | — | 1.0% | Jun 9, 2015 |
28Monitor | CVE-2006-6619Proof of concept | AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypassavg · antivirus plus firewall | High7.2 | — | 1.0% | Dec 18, 2006 |
- CVE-2018-1743164This week
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
CriticalCVSS 9.8Proof of conceptEPSS 84%comodo · unified threat management firewallJan 30, 2019
- CVE-2012-145647Plan
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
MediumCVSS 4.3No exploitEPSS 100%avg · avg anti-virusMar 21, 2012
- CVE-2012-145947Plan
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
MediumCVSS 4.3No exploitEPSS 100%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-144347Plan
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
MediumCVSS 4.3No exploitEPSS 100%cat · quick healMar 21, 2012
- CVE-2012-143046Plan
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-143146Plan
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2008-047046Plan
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.
CriticalCVSS 9.3Proof of conceptEPSS 31%comodo · comodo antivirusJan 29, 2008
- CVE-2012-146345Plan
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5
MediumCVSS 4.3No exploitEPSS 94%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-142945Plan
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.
MediumCVSS 4.3No exploitEPSS 92%comodo · comodo antivirusMar 21, 2012
- CVE-2011-512140Plan
The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not properly check whether unspecified X.509 certificates ar
CriticalCVSS 10.0No exploitEPSS 1%comodo · comodo internet securityAug 25, 2012
- CVE-2010-518540Plan
The Antivirus component in Comodo Internet Security before 5.3.174622.1216 does not check whether X.509 certificates in signed executable fi
CriticalCVSS 10.0No exploitEPSS 1%comodo · comodo internet securityAug 25, 2012
- CVE-2011-512340Plan
The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not check whether X.509 certificates in signed executable fi
CriticalCVSS 10.0No exploitEPSS 1%comodo · comodo internet securityAug 25, 2012
- CVE-2025-709733Monitor
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
HighCVSS 8.2No exploitEPSS 4%comodo · internet securityJul 6, 2025
- CVE-2014-963332Monitor
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers
HighCVSS 7.5Proof of conceptEPSS 8%comodo · backupFeb 3, 2015
- CVE-2025-709632Monitor
Comodo Internet Security Premium Manifest File cis_update_x64.xml integrity check
HighCVSS 8.2No exploitEPSS 0%comodo · internet securityJul 6, 2025
- CVE-2019-1821531Monitor
An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0.
HighCVSS 7.8No exploitEPSS 1%comodo · comodo internet securityNov 18, 2019
- CVE-2019-396931Monitor
Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Local Privilege Escalation due to CmdAgent's handling of COM clients.
HighCVSS 7.8No exploitEPSS 1%comodo · antivirusJul 17, 2019
- CVE-2022-3400831Monitor
Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation.
HighCVSS 7.8No exploitEPSS 0%comodo · antivirusJun 21, 2022
- CVE-2024-724831Monitor
Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%comodo · internet securityJul 29, 2024
- CVE-2024-725131Monitor
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%comodo · internet securityJul 29, 2024
- CVE-2024-725031Monitor
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%comodo · internet securityJul 29, 2024
- CVE-2024-725231Monitor
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%comodo · internet securityJul 29, 2024
- CVE-2024-724931Monitor
Comodo Firewall Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%comodo · firewallJul 29, 2024
- CVE-2014-787228Monitor
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to th
HighCVSS 7.2Proof of conceptEPSS 1%comodo · geekbuddyJun 9, 2015
- CVE-2006-661928Monitor
AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass
HighCVSS 7.2Proof of conceptEPSS 1%avg · antivirus plus firewallDec 18, 2006