Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Avg

First CVE: Dec 18, 2006Active for: 20 yearsTotal CVEs: 40
33.1
VTI Score
Medium

AVG maintains a focused antivirus product line that protects individual and small-business endpoints, presenting a moderate but concentrated attack surface in the consumer security space. The vendor's vulnerability profile centers on its core antivirus engine and related components, where exposure recurs through weakness classes including improper input validation, link-following issues, and NULL-pointer dereferences—the latter characteristic of parser and engine logic handling untrusted file formats and threat signatures. The antivirus role itself creates structural exposure: the software operates with elevated privileges and processes untrusted content from the network and disk, amplifying the impact of file-handling and validation flaws. Defenders deploying this vendor's products should maintain current patching cadence and monitor the antivirus tier as a critical perimeter component; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Avg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2006
19 years ago
Most Recent CVE
Nov 22, 2024
609 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1459MEDIUM
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10
Mar 21, 20124.371NONO
CVE-2012-1457MEDIUM
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka
Mar 21, 20124.370NONO
CVE-2012-1456MEDIUM
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.
Mar 21, 20124.369NONO
CVE-2012-1443MEDIUM
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio
Mar 21, 20124.369NONO
CVE-2012-1462MEDIUM
The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F
Mar 21, 20124.368NONO
CVE-2012-1461MEDIUM
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus
Mar 21, 20124.366NONO
CVE-2014-2956HIGH
ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement do
Jul 8, 20149.329NONO
CVE-2009-1784HIGH
The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeB
May 22, 200910.028NONO
CVE-2014-9632HIGH
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitra
Feb 6, 20157.227NOYES
CVE-2006-6619HIGH
AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by
Dec 18, 20067.227NOYES
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
55%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local15 (37.5%)
Network3 (7.5%)
Unknown22 (55.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (40.0%)
High2 (5.0%)
Unknown22 (55.0%)
User Interaction
None15 (37.5%)
Unknown22 (55.0%)
Required3 (7.5%)
Privileges Required
Low13 (32.5%)
High1 (2.5%)
None4 (10.0%)
Unknown22 (55.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Avg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Avg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Avg's Products

View all 4 CNAs →

Top CWEs