Intuit's vulnerability footprint concentrates across a modestly sized portfolio of tax-preparation and small-business accounting products including QuickBooks, TurboTax, and ProSeries, where the exposure reflects data-handling and file-access demands of financial software. The recurring weakness classes—chiefly information-disclosure issues, buffer-boundary violations, path-traversal flaws, and cleartext transmission of sensitive data—are characteristic of legacy desktop and web applications that manage and process personal financial records. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intuit over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6387HIGH Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping | Dec 15, 2007 | 9.3 | 54 | NO | YES |
CVE-2007-0322HIGH Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors. | Sep 5, 2007 | 9.3 | 25 | NO | NO |
CVE-2007-4471HIGH Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified | Sep 5, 2007 | 9.3 | 25 | NO | NO |
CVE-2018-11338HIGH Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information | Jul 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-3854HIGH An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 reques | Dec 3, 2018 | 7.1 | 23 | NO | NO |
CVE-2012-2418MEDIUM Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, | Apr 25, 2012 | 6.8 | 22 | NO | NO |
CVE-2018-14833MEDIUM Intuit Lacerte 2017 has Incorrect Access Control. | Jul 9, 2019 | 5.9 | 21 | NO | NO |
CVE-2010-5198MEDIUM Multiple untrusted search path vulnerabilities in Intuit QuickBooks 2010 allow local users to gain privileges via a Trojan horse (1) dbicudtx11.dll, (2) mfc90enu.dll, or (3) mfc90l | Sep 6, 2012 | 6.9 | 21 | NO | NO |
CVE-2001-0465MEDIUM TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive informat | Jun 18, 2001 | 4.6 | 18 | NO | NO |
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used | Apr 25, 2012 | 1.8 | 14 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intuit.
Media articles that mention a CVE ID that affects a product developed by Intuit — matched by CVE ID, not by vendor name.