AVG maintains a focused antivirus product line that protects individual and small-business endpoints, presenting a moderate but concentrated attack surface in the consumer security space. The vendor's vulnerability profile centers on its core antivirus engine and related components, where exposure recurs through weakness classes including improper input validation, link-following issues, and NULL-pointer dereferences—the latter characteristic of parser and engine logic handling untrusted file formats and threat signatures. The antivirus role itself creates structural exposure: the software operates with elevated privileges and processes untrusted content from the network and disk, amplifying the impact of file-handling and validation flaws. Defenders deploying this vendor's products should maintain current patching cadence and monitor the antivirus tier as a critical perimeter component; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Avg over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1459MEDIUM The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10 | Mar 21, 2012 | 4.3 | 71 | NO | NO |
CVE-2012-1457MEDIUM The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka | Mar 21, 2012 | 4.3 | 70 | NO | NO |
CVE-2012-1456MEDIUM The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6. | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1443MEDIUM The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1462MEDIUM The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F | Mar 21, 2012 | 4.3 | 68 | NO | NO |
CVE-2012-1461MEDIUM The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus | Mar 21, 2012 | 4.3 | 66 | NO | NO |
CVE-2014-2956HIGH ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement do | Jul 8, 2014 | 9.3 | 29 | NO | NO |
CVE-2009-1784HIGH The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeB | May 22, 2009 | 10.0 | 28 | NO | NO |
CVE-2014-9632HIGH The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitra | Feb 6, 2015 | 7.2 | 27 | NO | YES |
CVE-2006-6619HIGH AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by | Dec 18, 2006 | 7.2 | 27 | NO | YES |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avg.
Media articles that mention a CVE ID that affects a product developed by Avg — matched by CVE ID, not by vendor name.