VYPR

Antivirus

by AVG Technologies

CVEs (33)

  • CVE-2025-13032CriNov 11, 2025
    risk 0.64cvss 9.9epss 0.00

    Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

  • CVE-2023-5760HigNov 8, 2023
    risk 0.53cvss 8.2epss 0.00

    A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue…

  • CVE-2025-10101HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast…

  • CVE-2024-7237HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-7234HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2019-17093HigOct 23, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense…

  • CVE-2024-5803HigOct 3, 2024
    risk 0.49cvss 7.5epss 0.00

    The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.

  • CVE-2017-9977HigJul 12, 2017
    risk 0.49cvss 7.5epss 0.01

    AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files.

  • CVE-2022-4173HigDec 6, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.

  • CVE-2022-4294HigJan 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2017-5566MedMar 21, 2017
    risk 0.44cvss 6.7epss 0.01

    Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any AVG process via…

  • CVE-2023-1586MedApr 19, 2023
    risk 0.42cvss 6.5epss 0.00

    Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus version 22.11

  • CVE-2023-1585MedApr 19, 2023
    risk 0.42cvss 6.5epss 0.00

    Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG Antivirus version 22.11 and virus definitions from 14…

  • CVE-2019-18654MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.

  • CVE-2023-1587MedApr 19, 2023
    risk 0.38cvss 5.8epss 0.00

    Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11

  • CVE-2024-7236MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute…

  • CVE-2024-7235MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2020-13657MedJun 29, 2020
    risk 0.36cvss 5.5epss 0.00

    An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control of arbitrary files.

  • CVE-2024-9484MedOct 4, 2024
    risk 0.33cvss 5.1epss 0.00

    An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.

  • CVE-2024-9483MedOct 4, 2024
    risk 0.33cvss 5.1epss 0.00

    A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.

Page 1 of 2