Dr.Web maintains a modestly represented security software portfolio centered on antivirus and endpoint-protection products such as Dr.Web Antivirus and Security Space, which are deployed across consumer and enterprise environments. The recurring vulnerability patterns reflect the architectural demands of real-time threat scanning and signature verification: race conditions in concurrent processing, input-validation weaknesses in parser logic, cryptographic signature verification flaws, and uncontrolled search-path issues that can arise in privileged scanning contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Drweb over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1453MEDIUM The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee | Mar 21, 2012 | 4.3 | 67 | NO | NO |
CVE-2012-1454MEDIUM The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivi | Mar 21, 2012 | 4.3 | 61 | NO | NO |
CVE-2012-1447MEDIUM The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF | Mar 21, 2012 | 4.3 | 47 | NO | NO |
CVE-2021-28130HIGH Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses fire | Sep 24, 2021 | 7.8 | 25 | NO | NO |
CVE-2008-5526HIGH DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE i | Dec 12, 2008 | 9.3 | 24 | NO | NO |
CVE-2020-23967HIGH Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during au | Mar 8, 2021 | 7.8 | 20 | NO | NO |
CVE-2010-5159HIGH Race condition in Dr.Web Security Space Pro 6.0.0.03100 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blo | Aug 25, 2012 | 7.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drweb.
Media articles that mention a CVE ID that affects a product developed by Drweb — matched by CVE ID, not by vendor name.