Записи Bitdefender
107 опубликованных записей вендора bitdefender.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 21
- С записью об исправлении
- 2,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls9
- CWE-295 Improper Certificate Validation7
- CWE-59 Improper Link Resolution Before File Access ('Link Following')6
- CWE-918 Server-Side Request Forgery (SSRF)6
- CWE-426 Untrusted Search Path5
- CWE-787 Out-of-bounds Write5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
107 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2012-1459Эксплойта нет | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Средняя4,3 | — | 99,8 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1443Эксплойта нет | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Средняя4,3 | — | 99,6 % | 21 мар. 2012 г. |
47В плане | CVE-2007-5775Proof of concept | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024.bitdefender · antivirus · CWE-94 | Критическая9,8 | — | 26,9 % | 1 нояб. 2007 г. |
46В плане | CVE-2012-1457Эксплойта нет | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.anti-virus · vba32 · CWE-264 | Средняя4,3 | — | 98,3 % | 21 мар. 2012 г. |
46В плане | CVE-2012-1430Эксплойта нет | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Средняя4,3 | — | 96,0 % | 21 мар. 2012 г. |
46В плане | CVE-2012-1431Эксплойта нет | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Средняя4,3 | — | 96,0 % | 21 мар. 2012 г. |
45В плане | CVE-2012-1463Эксплойта нет | The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5ahnlab · v3 internet security · CWE-264 | Средняя4,3 | — | 94,2 % | 21 мар. 2012 г. |
45В плане | CVE-2012-1461Эксплойта нет | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Antanti-virus · vba32 · CWE-264 | Средняя4,3 | — | 91,7 % | 21 мар. 2012 г. |
41В плане | CVE-2021-3554Эксплойта нет | Improper Access Control vulnerability in the patchesUpdate APIbitdefender · endpoint security tools · CWE-284 | Критическая10,0 | — | 2,6 % | 24 нояб. 2021 г. |
40В плане | CVE-2008-5409Proof of concept | Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Securitbitdefender · antivirus · CWE-119 | Критическая9,3 | — | 11,1 % | 10 дек. 2008 г. |
40В плане | CVE-2018-8955Эксплойта нет | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which albitdefender · gravityzone · CWE-347 | Критическая9,8 | — | 4,3 % | 24 окт. 2018 г. |
40В плане | CVE-2019-17095Эксплойта нет | Bitdefender BOX 2 bootstrap download_image command injection vulnerabilitybitdefender · box 2 firmware · CWE-78 | Критическая9,8 | — | 4,2 % | 27 янв. 2020 г. |
40В плане | CVE-2019-17096Эксплойта нет | Bitdefender BOX 2 bootstrap get_image_size command injection vulnerabilitybitdefender · box 2 firmware · CWE-78 | Критическая9,8 | — | 2,1 % | 27 янв. 2020 г. |
39Наблюдать | CVE-2014-5350Proof of concept | Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files viabitdefender · gravityzone · CWE-22 | Средняя5,0 | — | 63,9 % | 19 авг. 2014 г. |
39Наблюдать | CVE-2007-6189Proof of concept | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execbitdefender · online anti-virus scanner · CWE-119 | Критическая9,3 | — | 8,1 % | 29 нояб. 2007 г. |
39Наблюдать | CVE-2017-8931Эксплойта нет | Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.bitdefender · gravityzone | Критическая9,8 | — | 1,5 % | 30 окт. 2018 г. |
39Наблюдать | CVE-2021-3823Эксплойта нет | Path traversal vulnerability in Bitdefender GravitZone Update Server in relay modebitdefender · gravityzone · CWE-22 | Критическая9,8 | — | 1,1 % | 28 окт. 2021 г. |
39Наблюдать | CVE-2022-2830Эксплойта нет | Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)bitdefender · gravityzone · CWE-502 | Критическая9,8 | — | 0,9 % | 5 сент. 2022 г. |
39Наблюдать | CVE-2024-2224Эксплойта нет | Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)bitdefender · endpoint security · CWE-22 | Критическая9,8 | — | 0,7 % | 9 апр. 2024 г. |
39Наблюдать | CVE-2024-2223Эксплойта нет | Incorrect Regular Expression in GravityZone Update Server (VA-11465)bitdefender · endpoint security · CWE-185 | Критическая9,8 | — | 0,5 % | 9 апр. 2024 г. |
39Наблюдать | CVE-2024-4177Эксплойта нет | Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)bitdefender · gravityzone · CWE-116 | Критическая9,8 | — | 0,4 % | 6 июн. 2024 г. |
38Наблюдать | CVE-2025-2244Эксплойта нет | Insecure PHP deserialization issue in GravityZone Console (VA-12634)bitdefender · gravityzone · CWE-502 | Критическая9,5 | — | 1,1 % | 4 апр. 2025 г. |
37Наблюдать | CVE-2017-17408Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018.bitdefender · internet security 2018 · CWE-190 | Высокая8,8 | — | 6,5 % | 21 дек. 2017 г. |
37Наблюдать | CVE-2024-13871Эксплойта нет | Unauthenticated Command Injection in Bitdefender BOX v1bitdefender · box firmware · CWE-77 | Критическая9,4 | — | 0,8 % | 12 мар. 2025 г. |
37Наблюдать | CVE-2025-1987Эксплойта нет | Stored XSS in Psono-Client via Malicious Vault Entry URLsesaqa · psono client · CWE-79 | Критическая9,3 | — | 0,6 % | 21 июн. 2025 г. |
- CVE-2012-145947В плане
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
СредняяCVSS 4,3Эксплойта нетEPSS 100 %ahnlab · v3 internet security21 мар. 2012 г.
- CVE-2012-144347В плане
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
СредняяCVSS 4,3Эксплойта нетEPSS 100 %cat · quick heal21 мар. 2012 г.
- CVE-2007-577547В плане
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024.
КритическаяCVSS 9,8Proof of conceptEPSS 27 %bitdefender · antivirus1 нояб. 2007 г.
- CVE-2012-145746В плане
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.
СредняяCVSS 4,3Эксплойта нетEPSS 98 %anti-virus · vba3221 мар. 2012 г.
- CVE-2012-143046В плане
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
СредняяCVSS 4,3Эксплойта нетEPSS 96 %bitdefender · bitdefender21 мар. 2012 г.
- CVE-2012-143146В плане
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
СредняяCVSS 4,3Эксплойта нетEPSS 96 %bitdefender · bitdefender21 мар. 2012 г.
- CVE-2012-146345В плане
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5
СредняяCVSS 4,3Эксплойта нетEPSS 94 %ahnlab · v3 internet security21 мар. 2012 г.
- CVE-2012-146145В плане
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant
СредняяCVSS 4,3Эксплойта нетEPSS 92 %anti-virus · vba3221 мар. 2012 г.
- CVE-2021-355441В плане
Improper Access Control vulnerability in the patchesUpdate API
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %bitdefender · endpoint security tools24 нояб. 2021 г.
- CVE-2008-540940В плане
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Securit
КритическаяCVSS 9,3Proof of conceptEPSS 11 %bitdefender · antivirus10 дек. 2008 г.
- CVE-2018-895540В плане
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which al
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bitdefender · gravityzone24 окт. 2018 г.
- CVE-2019-1709540В плане
Bitdefender BOX 2 bootstrap download_image command injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bitdefender · box 2 firmware27 янв. 2020 г.
- CVE-2019-1709640В плане
Bitdefender BOX 2 bootstrap get_image_size command injection vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bitdefender · box 2 firmware27 янв. 2020 г.
- CVE-2014-535039Наблюдать
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via
СредняяCVSS 5,0Proof of conceptEPSS 64 %bitdefender · gravityzone19 авг. 2014 г.
- CVE-2007-618939Наблюдать
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to exec
КритическаяCVSS 9,3Proof of conceptEPSS 8 %bitdefender · online anti-virus scanner29 нояб. 2007 г.
- CVE-2017-893139Наблюдать
Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bitdefender · gravityzone30 окт. 2018 г.
- CVE-2021-382339Наблюдать
Path traversal vulnerability in Bitdefender GravitZone Update Server in relay mode
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bitdefender · gravityzone28 окт. 2021 г.
- CVE-2022-283039Наблюдать
Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bitdefender · gravityzone5 сент. 2022 г.
- CVE-2024-222439Наблюдать
Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bitdefender · endpoint security9 апр. 2024 г.
- CVE-2024-222339Наблюдать
Incorrect Regular Expression in GravityZone Update Server (VA-11465)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bitdefender · endpoint security9 апр. 2024 г.
- CVE-2024-417739Наблюдать
Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %bitdefender · gravityzone6 июн. 2024 г.
- CVE-2025-224438Наблюдать
Insecure PHP deserialization issue in GravityZone Console (VA-12634)
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %bitdefender · gravityzone4 апр. 2025 г.
- CVE-2017-1740837Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018.
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %bitdefender · internet security 201821 дек. 2017 г.
- CVE-2024-1387137Наблюдать
Unauthenticated Command Injection in Bitdefender BOX v1
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %bitdefender · box firmware12 мар. 2025 г.
- CVE-2025-198737Наблюдать
Stored XSS in Psono-Client via Malicious Vault Entry URLs
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %esaqa · psono client21 июн. 2025 г.