quickheal records
17 published records for vendor quickheal.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write4
- CWE-427 Uncontrolled Search Path Element2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-521 Weak Password Requirements2
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2017-5005Proof of concept | Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Proquickheal · antivirus pro · CWE-787 | Critical9.8 | — | 9.5% | Jan 2, 2017 |
40Plan | CVE-2017-8773No exploit | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Outquickheal · antivirus pro · CWE-787 | Critical9.8 | — | 2.3% | May 4, 2017 |
39Monitor | CVE-2017-8775No exploit | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memquickheal · antivirus pro · CWE-787 | Critical9.8 | — | 1.2% | May 4, 2017 |
39Monitor | CVE-2017-8774No exploit | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memquickheal · antivirus pro · CWE-787 | Critical9.8 | — | 1.2% | May 4, 2017 |
38Monitor | CVE-2008-5524No exploit | CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an Hquickheal · cat quickheal · CWE-20 | Critical9.3 | — | 1.9% | Dec 12, 2008 |
32Monitor | CVE-2015-8285Proof of concept | The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.quickheal · total security · CWE-119 | High7.5 | — | 5.5% | Apr 20, 2017 |
31Monitor | CVE-2020-9362No exploit | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive.quickheal · antivirus for server · CWE-436 | High7.8 | — | 1.5% | Feb 24, 2020 |
31Monitor | CVE-2018-8090Proof of concept | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe)quickheal · antivirus pro · CWE-427 | High7.8 | — | 1.2% | Jul 25, 2018 |
31Monitor | CVE-2025-69875No exploit | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore pquickheal · total security · CWE-269 | High7.8 | — | 0.1% | Feb 3, 2026 |
30Monitor | CVE-2017-8776No exploit | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 16quickheal · antivirus pro | High7.5 | — | 0.9% | May 4, 2017 |
29Monitor | CVE-2022-31467No exploit | DLL Hijacking Vulnerability in Quick Heal Total Securityquickheal · total security · CWE-427 | High7.3 | — | 0.3% | May 23, 2022 |
28Monitor | CVE-2013-6767Proof of concept | Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denialquickheal · antivirus pro · CWE-119 | High7.2 | — | 1.3% | Dec 20, 2013 |
28Monitor | CVE-2009-4556Proof of concept | Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the quickheal · antivirus plus 2009 · CWE-264 | High7.2 | — | 0.7% | Jan 4, 2010 |
28Monitor | CVE-2022-31466No exploit | TOCTOU Vulnerability in Quick Heal Total Securityquickheal · total security · CWE-59 | High7.0 | — | 0.2% | May 23, 2022 |
26Monitor | CVE-2020-27587No exploit | Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-forcequickheal · total security · CWE-521 | Medium6.7 | — | 0.4% | Nov 30, 2020 |
23Monitor | CVE-2020-27586No exploit | Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.quickheal · total security · CWE-319 | Medium5.9 | — | 0.7% | Nov 30, 2020 |
17Monitor | CVE-2020-27585No exploit | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack onquickheal · total security · CWE-521 | Medium4.4 | — | 0.3% | Nov 30, 2020 |
- CVE-2017-500542Plan
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro
CriticalCVSS 9.8Proof of conceptEPSS 9%quickheal · antivirus proJan 2, 2017
- CVE-2017-877340Plan
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out
CriticalCVSS 9.8No exploitEPSS 2%quickheal · antivirus proMay 4, 2017
- CVE-2017-877539Monitor
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Mem
CriticalCVSS 9.8No exploitEPSS 1%quickheal · antivirus proMay 4, 2017
- CVE-2017-877439Monitor
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Mem
CriticalCVSS 9.8No exploitEPSS 1%quickheal · antivirus proMay 4, 2017
- CVE-2008-552438Monitor
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H
CriticalCVSS 9.3No exploitEPSS 2%quickheal · cat quickhealDec 12, 2008
- CVE-2015-828532Monitor
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
HighCVSS 7.5Proof of conceptEPSS 5%quickheal · total securityApr 20, 2017
- CVE-2020-936231Monitor
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive.
HighCVSS 7.8No exploitEPSS 2%quickheal · antivirus for serverFeb 24, 2020
- CVE-2018-809031Monitor
Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe)
HighCVSS 7.8Proof of conceptEPSS 1%quickheal · antivirus proJul 25, 2018
- CVE-2025-6987531Monitor
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore p
HighCVSS 7.8No exploitEPSS 0%quickheal · total securityFeb 3, 2026
- CVE-2017-877630Monitor
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 16
HighCVSS 7.5No exploitEPSS 1%quickheal · antivirus proMay 4, 2017
- CVE-2022-3146729Monitor
DLL Hijacking Vulnerability in Quick Heal Total Security
HighCVSS 7.3No exploitEPSS 0%quickheal · total securityMay 23, 2022
- CVE-2013-676728Monitor
Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denial
HighCVSS 7.2Proof of conceptEPSS 1%quickheal · antivirus proDec 20, 2013
- CVE-2009-455628Monitor
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the
HighCVSS 7.2Proof of conceptEPSS 1%quickheal · antivirus plus 2009Jan 4, 2010
- CVE-2022-3146628Monitor
TOCTOU Vulnerability in Quick Heal Total Security
HighCVSS 7.0No exploitEPSS 0%quickheal · total securityMay 23, 2022
- CVE-2020-2758726Monitor
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force
MediumCVSS 6.7No exploitEPSS 0%quickheal · total securityNov 30, 2020
- CVE-2020-2758623Monitor
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
MediumCVSS 5.9No exploitEPSS 1%quickheal · total securityNov 30, 2020
- CVE-2020-2758517Monitor
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on
MediumCVSS 4.4No exploitEPSS 0%quickheal · total securityNov 30, 2020