
CVE-2010-5174
https://notcve.org/view.php?id=CVE-2010-5174
25 Aug 2012 — Race condition in Prevx 3.0.5.143 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execut... • http://archives.neohapsis.com/archives/bugtraq/2010-05/0026.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2012-1441
https://notcve.org/view.php?id=CVE-2012-1441
21 Mar 2012 — The Microsoft EXE file parser in eSafe 7.0.17.0 and Prevx 3.0 allows remote attackers to bypass malware detection via an EXE file with a modified value in any of several e_ fields. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations. El analizador de archivos Microsoft EXE en eSafe v7.0.17.0, y Prevx 3.0 permite a atacantes remotos evitar la detección de malware a través de un archivo EX... • http://www.ieee-security.org/TC/SP2012/program.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-1444
https://notcve.org/view.php?id=CVE-2012-1444
21 Mar 2012 — The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations. El analizador de archivos ELF en eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, y Panda Antivirus 10.0.2.7 permite a... • http://osvdb.org/80429 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-5538
https://notcve.org/view.php?id=CVE-2008-5538
12 Dec 2008 — Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. Prevx Prevx1 2, cuando se utiliza Internet Explorer 6 o 7, permite a atacantes remotos eludir la detección de malware en un documento HTML colocando una cabe... • http://securityreason.com/securityalert/4723 • CWE-20: Improper Input Validation •

CVE-2005-2144
https://notcve.org/view.php?id=CVE-2005-2144
05 Jul 2005 — Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file. • http://secunia.com/advisories/15885 •

CVE-2005-2145
https://notcve.org/view.php?id=CVE-2005-2145
05 Jul 2005 — The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message. • http://secunia.com/advisories/15885 •

CVE-2004-1193
https://notcve.org/view.php?id=CVE-2004-1193
15 Dec 2004 — Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel's original SDT ServiceTable. • http://marc.info/?l=bugtraq&m=110118902823639&w=2 • CWE-264: Permissions, Privileges, and Access Controls •