Kaspersky's vulnerability profile centers on a focused portfolio of widely deployed endpoint-protection and internet-security products, which occupy a prominent position in the anti-malware and defense-software landscape. The vendor's disclosures cluster around application-layer and access-control weaknesses—including improper input validation, exposure of sensitive information, and cross-site request forgery—alongside cases where information classification is incomplete, reflecting the complexity of security-focused software that must parse untrusted data and manage user credentials. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching and deployment of updates across protected systems a practical defense priority. Defenders should monitor Kaspersky's release cycles for its flagship anti-virus and internet-security products and ensure endpoint deployments receive updates promptly; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaspersky over time
Of all the CVEs published by Kaspersky as a CNA, 20.6% affect products that Kaspersky develops as a vendor.
Of all the CVEs published that affect products developed by Kaspersky, 51.6% are self-published by Kaspersky as a CNA.
Signals from CVEs in this vendor scope (100 CVEs).
100 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1459MEDIUM The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10 | Mar 21, 2012 | 4.3 | 71 | NO | NO |
CVE-2004-0932HIGH McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via | Jan 27, 2005 | 7.5 | 71 | NO | YES |
CVE-2012-1457MEDIUM The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka | Mar 21, 2012 | 4.3 | 70 | NO | NO |
CVE-2012-1456MEDIUM The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6. | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1443MEDIUM The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protectio | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1442MEDIUM The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky | Mar 21, 2012 | 4.3 | 69 | NO | NO |
CVE-2012-1462MEDIUM The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F | Mar 21, 2012 | 4.3 | 68 | NO | NO |
CVE-2012-1453MEDIUM The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee | Mar 21, 2012 | 4.3 | 67 | NO | NO |
CVE-2012-1446MEDIUM The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antiv | Mar 21, 2012 | 4.3 | 67 | NO | NO |
CVE-2012-1461MEDIUM The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus | Mar 21, 2012 | 4.3 | 66 | NO | NO |
Signals from CVEs in this vendor scope (100 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaspersky.
Media articles that mention a CVE ID that affects a product developed by Kaspersky — matched by CVE ID, not by vendor name.