Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Intuit

First CVE: Jun 18, 2001Active for: 25 yearsTotal CVEs: 16
28.4
VTI Score
Low

Intuit's vulnerability footprint concentrates across a modestly sized portfolio of tax-preparation and small-business accounting products including QuickBooks, TurboTax, and ProSeries, where the exposure reflects data-handling and file-access demands of financial software. The recurring weakness classes—chiefly information-disclosure issues, buffer-boundary violations, path-traversal flaws, and cleartext transmission of sensitive data—are characteristic of legacy desktop and web applications that manage and process personal financial records. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
5.0
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Intuit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2001
25 years ago
Most Recent CVE
Jul 9, 2019
2,572 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-6387HIGH
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping
Dec 15, 20079.354NOYES
CVE-2007-0322HIGH
Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors.
Sep 5, 20079.325NONO
CVE-2007-4471HIGH
Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite arbitrary files via unspecified
Sep 5, 20079.325NONO
CVE-2018-11338HIGH
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information
Jul 31, 20187.524NONO
CVE-2018-3854HIGH
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 reques
Dec 3, 20187.123NONO
CVE-2012-2418MEDIUM
Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012,
Apr 25, 20126.822NONO
CVE-2018-14833MEDIUM
Intuit Lacerte 2017 has Incorrect Access Control.
Jul 9, 20195.921NONO
CVE-2010-5198MEDIUM
Multiple untrusted search path vulnerabilities in Intuit QuickBooks 2010 allow local users to gain privileges via a Trojan horse (1) dbicudtx11.dll, (2) mfc90enu.dll, or (3) mfc90l
Sep 6, 20126.921NONO
CVE-2001-0465MEDIUM
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive informat
Jun 18, 20014.618NONO
CVE-2012-2425LOW
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used
Apr 25, 20121.814NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
44%
25%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (6.3%)
Network2 (12.5%)
Unknown13 (81.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (12.5%)
High1 (6.3%)
Unknown13 (81.3%)
User Interaction
None3 (18.8%)
Unknown13 (81.3%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None2 (12.5%)
Unknown13 (81.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Intuit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Intuit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Intuit's Products

View all 3 CNAs →

Top CWEs