CVE-2009-1784
 
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.
El motor de análisis AVG 8.5 323, como se usa en varios productos antivirus AVG, incluida la Edición de red antivirus, la Edición de Internet Security Netzwerk, la Edición de servidor para Linux / FreeBSD, la Edición antivirus SBS y otros permite a los atacantes remotos evitar la detección de malware a través de un (1) archivo RAR y (2) ZIP especialmente diseñado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-05-22 CVE Reserved
- 2009-05-22 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://blog.zoller.lu/2009/04/avg-zip-evasion-bypass.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/503392/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/34895 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50426 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | <= 8.0.156 Search vendor "Avg" for product "Avg Anti-virus" and version " <= 8.0.156" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 6.0.710 Search vendor "Avg" for product "Avg Anti-virus" and version "6.0.710" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.0 Search vendor "Avg" for product "Avg Anti-virus" and version "7.0" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.0.251 Search vendor "Avg" for product "Avg Anti-virus" and version "7.0.251" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.0.323 Search vendor "Avg" for product "Avg Anti-virus" and version "7.0.323" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.1.308 Search vendor "Avg" for product "Avg Anti-virus" and version "7.1.308" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.1.407 Search vendor "Avg" for product "Avg Anti-virus" and version "7.1.407" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.5.51 Search vendor "Avg" for product "Avg Anti-virus" and version "7.5.51" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.5.448 Search vendor "Avg" for product "Avg Anti-virus" and version "7.5.448" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 7.5.476 Search vendor "Avg" for product "Avg Anti-virus" and version "7.5.476" | - |
Affected
| ||||||
Avg Search vendor "Avg" | Avg Anti-virus Search vendor "Avg" for product "Avg Anti-virus" | 8.0 Search vendor "Avg" for product "Avg Anti-virus" and version "8.0" | - |
Affected
|