Comodo develops a portfolio of endpoint security and network filtering products—including personal firewalls, antivirus engines, and DNS-based threat protection—that are widely deployed across consumer and small-business segments. The vendor's vulnerability profile recurs through application-layer and synchronization-related weakness classes, notably cross-site scripting in web-facing components, link-following flaws in file-handling logic, and race conditions in concurrent execution contexts, reflecting the complexity of marshaling user input and file access across security software boundaries. A moderate tendency toward public exploit availability characterizes the vendor's disclosures, consistent with the appeal of security appliances as reverse-engineering targets and the attention paid to endpoint protection bypass techniques. Defenders should maintain current patches for Comodo products on internet-facing or externally managed systems and monitor this vendor's advisories for potential authentication or sandbox-evasion vectors; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comodo over time
Signals from CVEs in this vendor scope (91 CVEs).
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17431CRITICAL Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL. | Jan 30, 2019 | 9.8 | 88 | NO | YES |
CVE-2012-1459MEDIUM The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10 | Mar 21, 2012 | 4.3 | 71 | NO | NO |
CVE-2012-1456MEDIUM The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6. | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1443MEDIUM The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1430MEDIUM The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (form | Mar 21, 2012 | 4.3 | 67 | NO | NO |
CVE-2012-1429MEDIUM The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Lin | Mar 21, 2012 | 4.3 | 66 | NO | NO |
CVE-2012-1463MEDIUM The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7. | Mar 21, 2012 | 4.3 | 65 | NO | NO |
CVE-2012-1431MEDIUM The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gatew | Mar 21, 2012 | 4.3 | 65 | NO | NO |
CVE-2008-0470HIGH A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method. | Jan 29, 2008 | 9.3 | 49 | NO | YES |
CVE-2014-9633HIGH The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL pointer dereference. | Feb 3, 2015 | 7.5 | 31 | NO | YES |
Signals from CVEs in this vendor scope (91 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comodo.
Media articles that mention a CVE ID that affects a product developed by Comodo — matched by CVE ID, not by vendor name.