Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-10180

EPSS 0.47% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-10180

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款ESET产品ESET AV parsing engine 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ESET Smart Security Premium等都是斯洛伐克ESET公司的产品。Smart Security Premium是一套杀毒软件。Internet Security是一套针对互联网安全的杀毒软件。NOD32 Antivirus是一套杀毒软件。ESET AV parsing engine是其中的一个解析引擎。 多款ESET产品中的ESET AV parsing engine存在安全漏洞。攻击者可借助归档文件中的BZ2 Checksum字段利用该漏洞绕过病毒检查。以下产品及版本受到影响:ES
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2020-10180

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-10180

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-03-05 · 35 CVEs total

CVE-2020-10098Zammad 跨站脚本漏洞
CVE-2019-20501D-Link DWL-2600AP 操作系统命令注入漏洞
CVE-2019-20107TestLink SQL注入漏洞
CVE-2020-9380IPTV Smarters WEB TV PLAYER 代码问题漏洞
CVE-2020-10107PHPGurukul Daily Expense Tracker System 跨站脚本漏洞
CVE-2020-10106PHPGurukul Daily Expense Tracker System SQL注入漏洞
CVE-2020-9370HUMAX HGA12R-02 BRGCAA 授权问题漏洞
CVE-2020-10096Zammad 信息泄露漏洞
CVE-2020-10097Zammad 安全漏洞
CVE-2020-10173Comtrend VR-3033 操作系统命令注入漏洞
CVE-2020-10099Zammad 跨站脚本漏洞
CVE-2020-10100Zammad 信息泄露漏洞
CVE-2020-10101Zammad 输入验证错误漏洞
CVE-2020-10102Zammad 安全漏洞
CVE-2020-10103Zammad 跨站脚本漏洞
CVE-2020-10104Zammad 信息泄露漏洞
CVE-2020-10105Zammad 信息泄露漏洞
CVE-2019-17645Centreon 信息泄露漏洞
CVE-2020-10185Yubico YubiKey Validation Server 安全漏洞
CVE-2020-6986Omron PLC CJ series 资源管理错误漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-10180

No comments yet


Leave a comment