← Vulnerability feed

Vulnerability record · CVE-2005-3664 · published 18 November 2005

CVE-2005-3664: F-secure anti-virus vulnerability

F Secure · F Secure Anti Virus

Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file.

7.5 CVSS 2.0 High EPSS 4.3% · top 9.2%
7.5CVSS 2.0 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3664 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2967F-secure anti-virus improper input validation vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scann…EPSS 4.8%10.0CVE-2007-0445Kaspersky lab kaspersky anti-virus vulnerabilityHeap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for Fil…EPSS 8.9%10.0CVE-2007-1112Kaspersky lab kaspersky anti-virus vulnerabilityKaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.…EPSS 4.9%10.0CVE-2006-6409F-secure anti-virus vulnerabilityF-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass vir…EPSS 3.7%10.0CVE-2005-3142Kaspersky lab kaspersky anti-virus vulnerabilityHeap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary co…EPSS 42%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2007-3300F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header …EPSS 3.7%9.3CVE-2007-1879Kaspersky lab kaspersky anti-virus vulnerabilityThe StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance …EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2005-3664), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.