Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Comodo

First CVE: Dec 18, 2006Active for: 20 yearsTotal CVEs: 91
41.1
VTI Score
High

Comodo develops a portfolio of endpoint security and network filtering products—including personal firewalls, antivirus engines, and DNS-based threat protection—that are widely deployed across consumer and small-business segments. The vendor's vulnerability profile recurs through application-layer and synchronization-related weakness classes, notably cross-site scripting in web-facing components, link-following flaws in file-handling logic, and race conditions in concurrent execution contexts, reflecting the complexity of marshaling user input and file access across security software boundaries. A moderate tendency toward public exploit availability characterizes the vendor's disclosures, consistent with the appeal of security appliances as reverse-engineering targets and the attention paid to endpoint protection bypass techniques. Defenders should maintain current patches for Comodo products on internet-facing or externally managed systems and monitor this vendor's advisories for potential authentication or sandbox-evasion vectors; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
91
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Comodo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2006
19 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (91 CVEs).

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-17431CRITICAL
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
Jan 30, 20199.888NOYES
CVE-2012-1459MEDIUM
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10
Mar 21, 20124.371NONO
CVE-2012-1456MEDIUM
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.
Mar 21, 20124.369NONO
CVE-2012-1443MEDIUM
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio
Mar 21, 20124.369NONO
CVE-2012-1430MEDIUM
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (form
Mar 21, 20124.367NONO
CVE-2012-1429MEDIUM
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Lin
Mar 21, 20124.366NONO
CVE-2012-1463MEDIUM
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.
Mar 21, 20124.365NONO
CVE-2012-1431MEDIUM
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gatew
Mar 21, 20124.365NONO
CVE-2008-0470HIGH
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.
Jan 29, 20089.349NOYES
CVE-2014-9633HIGH
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL pointer dereference.
Feb 3, 20157.531NOYES
View all 91 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products91 CVEs
63%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (15.4%)
Network37 (40.7%)
Unknown40 (44.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (51.6%)
High4 (4.4%)
Unknown40 (44.0%)
User Interaction
None16 (17.6%)
Unknown40 (44.0%)
Required35 (38.5%)
Privileges Required
Low16 (17.6%)
High0 (0.0%)
None35 (38.5%)
Unknown40 (44.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (91 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.1% of CVEs· 95th percentile
ExploitDB
7 CVEs
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Comodo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Comodo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Comodo's Products

View all 5 CNAs →

Top CWEs