Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kaspersky

First CVE: Oct 18, 2001Active for: 25 yearsTotal CVEs: 100
38.3
VTI Score
Medium

Kaspersky's vulnerability profile centers on a focused portfolio of widely deployed endpoint-protection and internet-security products, which occupy a prominent position in the anti-malware and defense-software landscape. The vendor's disclosures cluster around application-layer and access-control weaknesses—including improper input validation, exposure of sensitive information, and cross-site request forgery—alongside cases where information classification is incomplete, reflecting the complexity of security-focused software that must parse untrusted data and manage user credentials. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching and deployment of updates across protected systems a practical defense priority. Defenders should monitor Kaspersky's release cycles for its flagship anti-virus and internet-security products and ensure endpoint deployments receive updates promptly; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
100
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kaspersky over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2001
24 years ago
Most Recent CVE
Feb 29, 2024
876 days ago

Self-Reporting Analysis

Of all the CVEs published by Kaspersky as a CNA, 20.6% affect products that Kaspersky develops as a vendor.

20.6%
79.4%
Self-reported: 32 (20.6%)
Third-party: 123 (79.4%)

Of all the CVEs published that affect products developed by Kaspersky, 51.6% are self-published by Kaspersky as a CNA.

51.6%
48.4%
Self-published: 32 (51.6%)
Other CNAs: 30 (48.4%)

Products(29 total)

Top CVEs

Signals from CVEs in this vendor scope (100 CVEs).

100 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1459MEDIUM
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10
Mar 21, 20124.371NONO
CVE-2004-0932HIGH
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
CVE-2012-1457MEDIUM
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka
Mar 21, 20124.370NONO
CVE-2012-1456MEDIUM
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.
Mar 21, 20124.369NONO
CVE-2012-1443MEDIUM
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio
Mar 21, 20124.369NONO
CVE-2012-1442MEDIUM
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky
Mar 21, 20124.369NONO
CVE-2012-1462MEDIUM
The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F
Mar 21, 20124.368NONO
CVE-2012-1453MEDIUM
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee
Mar 21, 20124.367NONO
CVE-2012-1446MEDIUM
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antiv
Mar 21, 20124.367NONO
CVE-2012-1461MEDIUM
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus
Mar 21, 20124.366NONO
View all 100 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products100 CVEs
52%
40%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (17.0%)
Network24 (24.0%)
Unknown58 (58.0%)
Physical1 (1.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (41.0%)
High1 (1.0%)
Unknown58 (58.0%)
User Interaction
None28 (28.0%)
Unknown58 (58.0%)
Required14 (14.0%)
Privileges Required
Low15 (15.0%)
High1 (1.0%)
None26 (26.0%)
Unknown58 (58.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (100 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
19.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kaspersky.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kaspersky — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kaspersky's Products

View all 3 CNAs →

Top CWEs