CVE-2019-8286

Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kaspersky:anti-virus:*:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:free_anti-virus:*:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:small_office_security:*:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:total_security:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:49

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/109300 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/109300 - Third Party Advisory, VDB Entry
References () https://support.kaspersky.com/general/vulnerability.aspx?el=12430#110719 - Vendor Advisory () https://support.kaspersky.com/general/vulnerability.aspx?el=12430#110719 - Vendor Advisory

Information

Published : 2019-07-18 19:15

Updated : 2024-11-21 04:49


NVD link : CVE-2019-8286

Mitre link : CVE-2019-8286

CVE.ORG link : CVE-2019-8286


JSON object : View

Products Affected

kaspersky

  • free_anti-virus
  • small_office_security
  • total_security
  • internet_security
  • anti-virus
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor