Virusblokada Vba32 Antivirus vulnerabilities
5 known vulnerabilities affecting virusblokada/vba32_antivirus.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-23440HIGHCVSS 7.1v3.36.02024-02-13
CVE-2024-23440 [HIGH] CWE-125 CVE-2024-23440: Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL
Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 of memory from ar arbitrary user-supplied pointer.
cvelistv5nvd
CVE-2024-23439HIGHCVSS 7.1v3.36.02024-02-13
CVE-2024-23439 [HIGH] CWE-125 CVE-2024-23439: Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x
Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL codes of the Vba32m64.sys driver.
cvelistv5nvd
CVE-2024-23441MEDIUMCVSS 5.5v3.36.02024-01-29
CVE-2024-23441 [MEDIUM] CWE-125 CVE-2024-23441: Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A
Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.
cvelistv5nvd
CVE-2008-5546CRITICALCVSS 9.3v3.12.8.52008-12-12
CVE-2008-5546 [CRITICAL] CVE-2008-5546: VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypas
VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745
nvd
CVE-2007-5254HIGHCVSS 7.2v3.12.22007-10-06
CVE-2007-5254 [HIGH] CWE-264 CVE-2007-5254: VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation dire
VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.
nvd