Kaspersky

First CVE: Aug 25, 2017Active for: 9 years
155
CVEs Published
More CVEs Published than 76% of tracked CNAs
15.5
Avg CVEs / Year
More Avg CVEs / Year than 63% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.6%
In CISA KEV
Higher KEV Rate than 86% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Kaspersky as a CNA, 20.6% affect products that Kaspersky develops as a vendor.

20.6%
79.4%
Self-reported: 32Third-party: 123

Of all the CVEs published that affect products developed by Kaspersky, 51.6% are self-published by Kaspersky as a CNA.

51.6%
48.4%
Self-published: 32Published by other CNAs: 30

Trends Over Time

The number and severity of CVEs published by Kaspersky over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2017
8 years ago
Most Recent CVE
May 15, 2026
70 days ago

Top CVEs

All CVEs published by Kaspersky as a CNA, regardless of affected vendor or product.

155 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate websit
May 15, 20269.878YESNO
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure imple
Aug 6, 20258.745NOYES
TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution
Oct 29, 20199.839NONO
LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execu
Dec 19, 20188.139NONO
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code e
Dec 19, 20189.838NONO
TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via netwo
Oct 29, 20199.837NONO
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the we
Oct 12, 20209.835NONO
LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution
Dec 19, 20189.835NONO
LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execu
Dec 19, 20189.835NONO
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable vi
Oct 29, 20199.834NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA155 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local20 (12.9%)
Network131 (84.5%)
Unknown0 (0.0%)
Physical4 (2.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low148 (95.5%)
High7 (4.5%)
Unknown0 (0.0%)
User Interaction
None131 (84.5%)
Unknown0 (0.0%)
Required24 (15.5%)
Privileges Required
Low27 (17.4%)
High8 (5.2%)
None120 (77.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (155 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 86th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Kaspersky as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Kaspersky as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs