← Vulnerability feed

Vulnerability record · CVE-2005-3142 · published 5 October 2005

CVE-2005-3142: Kaspersky lab kaspersky anti-virus vulnerability

KKaspersky Lab · Kaspersky Anti Virus

Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header.

10.0 CVSS 2.0 High EPSS 42% · top 1.4%
10.0CVSS 2.0 base score
42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3142 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-0445Kaspersky lab kaspersky anti-virus vulnerabilityHeap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for Fil…EPSS 8.9%10.0CVE-2007-1112Kaspersky lab kaspersky anti-virus vulnerabilityKaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.…EPSS 4.9%9.3CVE-2007-1879Kaspersky lab kaspersky anti-virus vulnerabilityThe StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance …EPSS 3.3%7.8CVE-2006-1091Kaspersky lab kaspersky anti-virus vulnerabilityKaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.EPSS 2.9%7.5CVE-2005-3664F-secure anti-virus vulnerabilityHeap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F…EPSS 4.3%7.5CVE-2004-0937Archive zip vulnerabilitySophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…EPSS 15%7.5CVE-2004-0932McAfee Anti-Virus Engine DATS driver bypass via malformed compressed fileThe McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files…EPSS 63%analysed7.5CVE-2004-0933Archive zip vulnerabilityComputer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content M…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2005-3142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.