Quickheal's vulnerability footprint centers on a focused line of endpoint protection and antivirus products spanning consumer and server platforms, including Total Security, Antivirus Pro, and Internet Security. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and reflect recurring weaknesses in memory-safety boundaries, search-path handling, credential management, and information disclosure—issues endemic to security software that operates at system privilege levels and interfaces directly with untrusted input. Defenders should prioritize patches for this vendor's products, particularly in server deployments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quickheal over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8775CRITICAL Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed | May 4, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-8774CRITICAL Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed | May 4, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-8773CRITICAL Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to | May 4, 2017 | 9.8 | 31 | NO | NO |
CVE-2013-6767HIGH Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denial of service (process crash) via a long * | Dec 20, 2013 | 7.2 | 31 | NO | YES |
CVE-2015-8285HIGH The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service. | Apr 20, 2017 | 7.5 | 30 | NO | YES |
CVE-2017-5005CRITICAL Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows r | Jan 2, 2017 | 9.8 | 28 | NO | NO |
CVE-2009-4556HIGH Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users | Jan 4, 2010 | 7.2 | 27 | NO | YES |
CVE-2020-9362HIGH The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Mul | Feb 24, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-8090HIGH Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Qu | Jul 25, 2018 | 7.8 | 25 | NO | NO |
CVE-2017-8776HIGH Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation t | May 4, 2017 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quickheal.
Media articles that mention a CVE ID that affects a product developed by Quickheal — matched by CVE ID, not by vendor name.