Bitdefender maintains a focused portfolio of endpoint protection, threat management, and consumer security products—including Total Security, GravityZone, and Endpoint Security Tools—that operate across enterprise and consumer deployments and handle sensitive system and network traffic. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged access and trust these products command within protected systems. The exposure recurs through weakness classes including server-side request forgery, improper certificate validation, and input-validation flaws that are characteristic of security software's deep integration with operating systems and its role in parsing untrusted security-relevant data. Defenders should treat Bitdefender advisories with priority, since vulnerabilities in endpoint protection tools directly undermine the systems they are meant to defend. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitdefender over time
Of all the CVEs published by Bitdefender as a CNA, 66.0% affect products that Bitdefender develops as a vendor.
Of all the CVEs published that affect products developed by Bitdefender, 66.0% are self-published by Bitdefender as a CNA.
Signals from CVEs in this vendor scope (106 CVEs).
106 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1459MEDIUM The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10 | Mar 21, 2012 | 4.3 | 71 | NO | NO |
CVE-2012-1457MEDIUM The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka | Mar 21, 2012 | 4.3 | 70 | NO | NO |
CVE-2012-1443MEDIUM The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1430MEDIUM The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (form | Mar 21, 2012 | 4.3 | 67 | NO | NO |
CVE-2012-1461MEDIUM The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus | Mar 21, 2012 | 4.3 | 66 | NO | NO |
CVE-2012-1463MEDIUM The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7. | Mar 21, 2012 | 4.3 | 65 | NO | NO |
CVE-2012-1431MEDIUM The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gatew | Mar 21, 2012 | 4.3 | 65 | NO | NO |
CVE-2014-5350MEDIUM Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter | Aug 19, 2014 | 5.0 | 64 | NO | YES |
CVE-2007-5775CRITICAL Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vag | Nov 1, 2007 | 9.8 | 55 | NO | YES |
CVE-2008-5409HIGH Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Ser | Dec 10, 2008 | 9.3 | 38 | NO | YES |
Signals from CVEs in this vendor scope (106 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitdefender.
Media articles that mention a CVE ID that affects a product developed by Bitdefender — matched by CVE ID, not by vendor name.