Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.
This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104.
This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to Avira scan engine build 8.3.70.104 or any later engine release. Builds at or above 8.3.70.104 include the fix.
Workaround
No workaround given by the vendor.
References
History
Sat, 13 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gen Digital
Gen Digital avira Antivirus |
|
| Vendors & Products |
Gen Digital
Gen Digital avira Antivirus |
Fri, 12 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104. | |
| Title | Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file | |
| Weaknesses | CWE-190 CWE-787 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GEN
Published:
Updated: 2026-06-12T22:16:01.317Z
Reserved: 2025-12-05T10:54:10.986Z
Link: CVE-2025-14098
No data.
Status : Received
Published: 2026-06-12T23:16:27.350
Modified: 2026-06-12T23:16:27.350
Link: CVE-2025-14098
No data.
OpenCVE Enrichment
Updated: 2026-06-13T12:29:18Z