3 results (0.009 seconds)

CVSS: 10.0EPSS: 14%CPEs: 2EXPL: 0

Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an "integer cast around." Desbordamiento de búfer en el motor de análisis sintáctico de ficheros en el Antivirus Avira Antivir anterior al 7.03.00.09 permite a atacantes remotos ejecutar código de su elección a través de un fichero LZH modificado, resultado de un "redondeo de conversión a entero". • http://forum.antivir-pe.de/thread.php?threadid=22528 http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063624.html http://osvdb.org/36712 http://secunia.com/advisories/25417 http://securityreason.com/securityalert/2764 http://securitytracker.com/id?1018131 http://www.nruns.com/advisories/%5Bn.runs-SA-2007.010%5D%20-%20Avira%20Antivir%20Antivirus%20LZH%20parsing%20Arbitrary%20Code%20Execution%20Advisory.txt http://www.securityfocus.com/archive/1/469805/100/0/threaded http://www •

CVSS: 7.8EPSS: 11%CPEs: 2EXPL: 0

Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed TAR archive. El Antivirus Avira Antivir anterior al 7.03.00.09 permite a atacantes remotos provocar una denegación de servicio (bucle infinito y agotamiento de CPU) a través de un archivo TAR mal formado. • http://forum.antivir-pe.de/thread.php?threadid=22528 http://osvdb.org/36711 http://secunia.com/advisories/25417 http://www.nruns.com/advisories/%5Bn.runs-SA-2007.012%5D%20-%20Avira%20Antivir%20Antivirus%20TAR%20parsing%20Infinite%20Loop%20Advisory.txt http://www.securityfocus.com/archive/1/470042/100/0/threaded http://www.securityfocus.com/bid/24187 http://www.securityfocus.com/bid/24239 http://www.securitytracker.com/id?1018137 http://www.vupen.com/english/advisories/2007/1971 •

CVSS: 7.8EPSS: 6%CPEs: 2EXPL: 0

The file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a crafted UPX compressed file, which triggers a divide-by-zero error. El motor de análisis sintáctico de ficheros del Avira Antivir Antivirus anterior al 7.04.00.24 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) a través de un fichero comprimido UPX manipulado, lo que dispara un error de "división por cero". • http://forum.antivir-pe.de/thread.php?threadid=22528 http://marc.info/?l=full-disclosure&m=118040810718045&w=2 http://osvdb.org/36710 http://secunia.com/advisories/25417 http://www.nruns.com/advisories/%5Bn.runs-SA-2007.011%5D%20-%20Avira%20Antivir%20Antivirus%20UPX%20parsing%20Divide%20by%20Zero%20Advisory.txt http://www.securityfocus.com/archive/1/469880/100/0/threaded http://www.securityfocus.com/bid/24187 http://www.securitytracker.com/id?1018132 http://www.vupen.com/e •