VYPR
Vendor

Comodo

Products
17
CVEs
94
Across products
119
Status
Private

Products

17

Recent CVEs

94
View all 94 CVEs →
  • CVE-2018-17431CriJan 30, 2019
    risk 0.73cvss 9.8epss 0.84

    Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.

  • CVE-2025-7097HigJul 6, 2025
    risk 0.53cvss 8.1epss 0.05

    A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation of the argument binary/params…

  • CVE-2025-7096HigJul 6, 2025
    risk 0.53cvss 8.1epss 0.00

    A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation leads to improper validation of integrity check…

  • CVE-2016-20090HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute…

  • CVE-2016-20088HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon…

  • CVE-2024-7252HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2024-7251HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2024-7250HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2024-7249HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system…

  • CVE-2024-7248HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2022-34008HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.

  • CVE-2019-18215HigNov 18, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product directory. This DLL is then loaded into a high-privileged…

  • CVE-2019-3969HigJul 17, 2019
    risk 0.51cvss 7.8epss 0.01

    Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Local Privilege Escalation due to CmdAgent's handling of COM clients. A local process can bypass the signature check enforced by CmdAgent via process hollowing which can then allow the process to invoke sensitive COM…

  • CVE-2026-49494HigJun 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixed header's payload length field) by the size of each IPv6 extension header…

  • CVE-2019-25422HigFeb 19, 2026
    risk 0.47cvss 7.2epss 0.00

    Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target parameter for reflected XSS or the remark parameter for…

  • CVE-2019-25419HigFeb 19, 2026
    risk 0.47cvss 7.2epss 0.00

    Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute…

  • CVE-2019-25405HigFeb 19, 2026
    risk 0.47cvss 7.2epss 0.00

    Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers can send POST requests to the license activation endpoint with script payloads in…

  • CVE-2019-14270HigJul 25, 2019
    risk 0.46cvss 7.1epss 0.00

    Comodo Antivirus through 12.0.0.6870, Comodo Firewall through 12.0.0.6870, and Comodo Internet Security Premium through 12.0.0.6870, with the Comodo Container feature, are vulnerable to Sandbox Escape.

  • CVE-2019-25404MedFeb 19, 2026
    risk 0.42cvss 6.4epss 0.00

    Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input through admin management parameters. Attackers can inject script payloads in the admin_name, name, and…

  • CVE-2019-25403MedFeb 19, 2026
    risk 0.42cvss 6.4epss 0.00

    Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the comment parameter. Attackers can inject JavaScript code through the admin_profiles endpoint that…