VYPR

Vendor CVEs

Eset

All CVEs

77 total · sorted by risk
  • CVE-2004-0936Jan 27, 2005
    risk 0.04cvss —epss 0.15

    RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

  • CVE-2004-0934Jan 27, 2005
    risk 0.04cvss —epss 0.15

    Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

  • CVE-2004-0935Jan 27, 2005
    risk 0.04cvss —epss 0.15

    Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

  • CVE-2008-7107Aug 28, 2009
    risk 0.03cvss —epss 0.01

    easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request to the \\.\easdrv device interface.

  • CVE-2008-5724Dec 26, 2008
    risk 0.03cvss —epss 0.01

    The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.

  • CVE-2008-4451Oct 6, 2008
    risk 0.03cvss —epss 0.01

    The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer.

  • CVE-2007-2852May 24, 2007
    risk 0.01cvss —epss 0.07

    Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name.

  • CVE-2026-10610HigJul 24, 2026
    risk 0.00cvss —epss 0.00

    Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

  • CVE-2026-7483HigJul 24, 2026
    risk 0.00cvss —epss 0.00

    Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

  • CVE-2026-6424MedJul 16, 2026
    risk 0.00cvss —epss 0.00

    Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

  • CVE-2026-6423HigJul 16, 2026
    risk 0.00cvss —epss 0.00

    A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.

  • CVE-2014-4974Nov 4, 2014
    risk 0.00cvss —epss 0.01

    The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.

  • CVE-2014-4973Sep 23, 2014
    risk 0.00cvss —epss 0.01

    The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL…

  • CVE-2009-0548Feb 12, 2009
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Additional Report Settings interface in ESET Remote Administrator before 3.0.105 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party…

  • CVE-2008-5534Dec 12, 2008
    risk 0.00cvss —epss 0.03

    ESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a…

  • CVE-2008-5527Dec 12, 2008
    risk 0.00cvss —epss 0.02

    ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a…

  • CVE-2008-5425Dec 11, 2008
    risk 0.00cvss —epss 0.02

    ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other…

  • CVE-2007-3971Jul 25, 2007
    risk 0.00cvss —epss 0.03

    Integer overflow in ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted ASPACK packed file, which triggers an infinite loop.

  • CVE-2007-3970Jul 25, 2007
    risk 0.00cvss —epss 0.06

    Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.

  • CVE-2007-3972Jul 25, 2007
    risk 0.00cvss —epss 0.03

    ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service via a crafted (1) ASPACK or (2) FSG packed file, which triggers a divide-by-zero error.

  • CVE-2006-6676Dec 21, 2006
    risk 0.00cvss —epss 0.06

    Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

  • CVE-2006-6677Dec 21, 2006
    risk 0.00cvss —epss 0.02

    ESET NOD32 Antivirus before 1.1743 allows remote attackers to cause a denial of service (crash) via a crafted .CHM file that triggers a divide-by-zero error.

  • CVE-2006-0951Apr 8, 2006
    risk 0.00cvss —epss 0.00

    The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspecified attack vectors.

  • CVE-2006-1649Apr 6, 2006
    risk 0.00cvss —epss 0.00

    The "restore to" selection in the "quarantine a file" capability of ESET NOD32 before 2.51.26 allows a restore to any directory that permits read access by the invoking user, which allows local users to create new files despite write-access directory permissions.

  • CVE-2005-3212Oct 14, 2005
    risk 0.00cvss —epss 0.02

    Multiple interpretation error in unspecified versions of NOD32 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar…

  • CVE-2005-2903Sep 14, 2005
    risk 0.00cvss —epss 0.04

    Heap-based buffer overflow in NOD32 2.5 with nod32.002 1.033 build 1127, with active scanning enabled, allows remote attackers to execute arbitrary code via an ARJ archive containing a file with a long filename.

  • CVE-2003-0062Feb 19, 2003
    risk 0.00cvss —epss 0.01

    Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.

Page 2 of 2