panda records
24 published records for vendor panda.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-399 Resource Management Errors3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2007-3026No exploit | Integer overflow in Panda Software AdminSecure allows remote attackers to execute arbitrary code via crafted packets with modified length vapanda · adminsecure | Critical9.3 | — | 9.5% | Jul 25, 2007 |
39Monitor | CVE-2008-3155Proof of concept | Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denipanda · panda activescan · CWE-119 | Critical9.3 | — | 7.7% | Jul 11, 2008 |
39Monitor | CVE-2009-3735No exploit | The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads softpanda · panda activescan · CWE-94 | Critical9.3 | — | 5.7% | Feb 11, 2010 |
39Monitor | CVE-2007-3969No exploit | Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from panda · panda antivirus | Critical9.3 | — | 5.7% | Jul 25, 2007 |
38Monitor | CVE-2008-3156Proof of concept | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cpanda · panda activescan · CWE-264 | Critical9.3 | — | 4.1% | Jul 11, 2008 |
32Monitor | CVE-2005-3922No exploit | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a craftedpanda · panda activescan | High7.5 | — | 5.6% | Nov 30, 2005 |
32Monitor | CVE-2007-1673No exploit | unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite looamavis · amavis · CWE-399 | High7.8 | — | 3.2% | May 8, 2007 |
32Monitor | CVE-2007-1670No exploit | Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direnpanda · panda activescan | High7.8 | — | 3.0% | May 8, 2007 |
31Monitor | CVE-2004-1904Proof of concept | Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property fopanda · activescan | High7.5 | — | 4.9% | Dec 31, 2004 |
28Monitor | CVE-2008-1471Proof of concept | The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system cpanda · panda antivirus and firewall · CWE-399 | High7.2 | — | 1.1% | Mar 24, 2008 |
28Monitor | CVE-2000-0541No exploit | The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.panda · panda antivirus | High7.2 | — | 0.7% | Jun 17, 2000 |
28Monitor | CVE-2006-4657No exploit | Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with panda · panda platinum internet security | High7.2 | — | 0.4% | Sep 8, 2006 |
27Monitor | CVE-2007-4191Proof of concept | Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users tpanda · panda antivirus | Medium6.9 | — | 0.8% | Aug 7, 2007 |
26Monitor | CVE-2006-5966No exploit | Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar methodpanda · activescan · CWE-399 | Medium6.4 | — | 1.8% | Nov 17, 2006 |
21Monitor | CVE-2006-5967No exploit | Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and executpanda · activescan | Medium5.1 | — | 2.4% | Nov 17, 2006 |
21Monitor | CVE-2006-4658No exploit | Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if panda · panda platinum internet security | Medium5.0 | — | 2.1% | Sep 8, 2006 |
21Monitor | CVE-2006-4659No exploit | The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, whicpanda · panda platinum internet security | Medium5.0 | — | 2.1% | Sep 8, 2006 |
21Monitor | CVE-2005-3230No exploit | Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious epanda · activescan | Medium5.1 | — | 1.7% | Oct 14, 2005 |
21Monitor | CVE-2004-1905No exploit | ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.panda · activescan | Medium5.0 | — | 1.7% | Dec 31, 2004 |
20Monitor | CVE-2005-3380No exploit | Multiple interpretation error in Panda Titanium 2005 4.02.01 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, panda · titanium 2005 | Medium5.0 | — | 1.4% | Oct 30, 2005 |
20Monitor | CVE-2001-1149No exploit | Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a mapanda · panda antivirus platinum | Medium5.0 | — | 1.3% | Aug 21, 2001 |
18Monitor | CVE-2006-4295Proof of concept | Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script opanda · panda activescan | Medium4.3 | — | 1.8% | Aug 22, 2006 |
18Monitor | CVE-2000-0265No exploit | Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.panda · panda security | Medium4.6 | — | 0.5% | Apr 17, 2000 |
8Monitor | CVE-2000-0264Proof of concept | Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file orpanda · panda security | Low2.1 | — | 0.7% | Apr 17, 2000 |
- CVE-2007-302640Plan
Integer overflow in Panda Software AdminSecure allows remote attackers to execute arbitrary code via crafted packets with modified length va
CriticalCVSS 9.3No exploitEPSS 9%panda · adminsecureJul 25, 2007
- CVE-2008-315539Monitor
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a deni
CriticalCVSS 9.3Proof of conceptEPSS 8%panda · panda activescanJul 11, 2008
- CVE-2009-373539Monitor
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads soft
CriticalCVSS 9.3No exploitEPSS 6%panda · panda activescanFeb 11, 2010
- CVE-2007-396939Monitor
Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from
CriticalCVSS 9.3No exploitEPSS 6%panda · panda antivirusJul 25, 2007
- CVE-2008-315638Monitor
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary c
CriticalCVSS 9.3Proof of conceptEPSS 4%panda · panda activescanJul 11, 2008
- CVE-2005-392232Monitor
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted
HighCVSS 7.5No exploitEPSS 6%panda · panda activescanNov 30, 2005
- CVE-2007-167332Monitor
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loo
HighCVSS 7.8No exploitEPSS 3%amavis · amavisMay 8, 2007
- CVE-2007-167032Monitor
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a diren
HighCVSS 7.8No exploitEPSS 3%panda · panda activescanMay 8, 2007
- CVE-2004-190431Monitor
Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property fo
HighCVSS 7.5Proof of conceptEPSS 5%panda · activescanDec 31, 2004
- CVE-2008-147128Monitor
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system c
HighCVSS 7.2Proof of conceptEPSS 1%panda · panda antivirus and firewallMar 24, 2008
- CVE-2000-054128Monitor
The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.
HighCVSS 7.2No exploitEPSS 1%panda · panda antivirusJun 17, 2000
- CVE-2006-465728Monitor
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with
HighCVSS 7.2No exploitEPSS 0%panda · panda platinum internet securitySep 8, 2006
- CVE-2007-419127Monitor
Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users t
MediumCVSS 6.9Proof of conceptEPSS 1%panda · panda antivirusAug 7, 2007
- CVE-2006-596626Monitor
Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method
MediumCVSS 6.4No exploitEPSS 2%panda · activescanNov 17, 2006
- CVE-2006-596721Monitor
Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execut
MediumCVSS 5.1No exploitEPSS 2%panda · activescanNov 17, 2006
- CVE-2006-465821Monitor
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if
MediumCVSS 5.0No exploitEPSS 2%panda · panda platinum internet securitySep 8, 2006
- CVE-2006-465921Monitor
The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, whic
MediumCVSS 5.0No exploitEPSS 2%panda · panda platinum internet securitySep 8, 2006
- CVE-2005-323021Monitor
Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious e
MediumCVSS 5.1No exploitEPSS 2%panda · activescanOct 14, 2005
- CVE-2004-190521Monitor
ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.
MediumCVSS 5.0No exploitEPSS 2%panda · activescanDec 31, 2004
- CVE-2005-338020Monitor
Multiple interpretation error in Panda Titanium 2005 4.02.01 allows remote attackers to bypass virus scanning via a file such as BAT, HTML,
MediumCVSS 5.0No exploitEPSS 1%panda · titanium 2005Oct 30, 2005
- CVE-2001-114920Monitor
Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a ma
MediumCVSS 5.0No exploitEPSS 1%panda · panda antivirus platinumAug 21, 2001
- CVE-2006-429518Monitor
Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script o
MediumCVSS 4.3Proof of conceptEPSS 2%panda · panda activescanAug 22, 2006
- CVE-2000-026518Monitor
Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.
MediumCVSS 4.6No exploitEPSS 0%panda · panda securityApr 17, 2000
- CVE-2000-02648Monitor
Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or
LowCVSS 2.1Proof of conceptEPSS 1%panda · panda securityApr 17, 2000