
CVE-2016-4306
https://notcve.org/view.php?id=CVE-2016-4306
06 Jan 2017 — Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability. Existen múltiples fugas de información en varios manejadores IOCTL del control... • http://securitytracker.com/id/1036702 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-4329
https://notcve.org/view.php?id=CVE-2016-4329
06 Jan 2017 — A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism. Existe una vulnerabilidad local de denegación de servicio en la funcionalidad de manejo de mensajes de difusión de ventanas del software Kaspersky Anti-Virus. Enviando ciertos mensajes de ventana no manipulados, un atacante puede pro... • http://www.securityfocus.com/bid/92771 • CWE-20: Improper Input Validation •

CVE-2017-5005
https://notcve.org/view.php?id=CVE-2017-5005
02 Jan 2017 — Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation. Desbordamiento de búfer basado en pila en Quick Heal Internet Security 10.1.0.316 y versiones anteriores, Total Security 10.1.0.316 y versiones anteriores y Ant... • https://github.com/payatu/QuickHeal • CWE-787: Out-of-bounds Write •

CVE-2016-10898 – Total Security <= 3.4 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-10898
25 Jul 2016 — The total-security plugin before 3.4.1 for WordPress has XSS. El plugin total-security versiones anteriores a 3.4.1 para WordPress, presenta una vulnerabilidad de tipo XSS. The total-security plugin before 3.4.1 for WordPress has XSS via several parameters. • https://wordpress.org/plugins/total-security/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-10899 – Total Security <= 3.4.0 - Unauthenticated Settings Change
https://notcve.org/view.php?id=CVE-2016-10899
25 Jul 2016 — The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability. El plugin total-security versiones anteriores a 3.4.1 para WordPress, presenta una vulnerabilidad de cambio de configuración. • https://wordpress.org/plugins/total-security/#developers • CWE-20: Improper Input Validation CWE-862: Missing Authorization •

CVE-2014-9643 – K7 Computing (Multiple Products) - Arbitrary Write Privilege Escalation
https://notcve.org/view.php?id=CVE-2014-9643
05 Feb 2015 — K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call. K7Sentry.sys en K7 Computing Ultimate Security, Anti-Virus Plus, y Total Security anterior a 14.2.0.253 permite a usuarios locales escribir a localizaciones de memoria arbitrarias, y como consecuencia ganar privilegio... • https://packetstorm.news/files/id/130246 • CWE-264: Permissions, Privileges, and Access Controls •