CVE-2025-14098: Heap Buffer Overflow Vulnerability in Avira Antivirus Engine (Pre-8.3.70.104)
Summary
A heap buffer out-of-bounds write vulnerability (CVE-2025-14098) exists in the Avira Antivirus engine due to an integer overflow when scanning malformed MS-DOS executable files. This flaw could allow local execution of code or denial-of-service of the antivirus engine process. The vulnerability affects Avira Antivirus on Windows, macOS, and Linux for engine builds before version 8.3.70.104.
Source

Key quotes
· 2 pulledHeap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.
This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104.
You might also wanna read
Technical Analysis of CVE-2025-53149: Heap-based Buffer Overflow in Windows Kernel Streaming Driver
Researchers discovered CVE-2025-53149, a heap-based buffer overflow vulnerability in the Windows Kernel Streaming WOW Thunk Service Driver (
Heap-Buffer-Overflow Vulnerability Discovered in FFmpeg's EXIF Writer for Image Formats
The article details the discovery of a four-byte heap-buffer-overflow vulnerability in FFmpeg's EXIF writer when processing extra IFD (Image
Proof-of-Concept Exploit Released for Critical NGINX Heap Buffer Overflow (CVE-2026-42945)
A proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow vulnerability in NGINX's ngx_http_rewrite_module that has exi
Critical Buffer Overflow Vulnerability Discovered in cURL Cookie Parsing Mechanism
A security researcher discovered a critical stack-based buffer overflow vulnerability in cURL's cookie parsing mechanism that can lead to re
Memory Disclosure Vulnerability Discovered in Ruby 4.0.0's Array#pack Method
A security researcher discovered a memory disclosure vulnerability in Ruby 4.0.0's Array#pack method that allows reading memory beyond alloc
Exploiting CVE-2024-50264: Using Kernel-Hack-Drill to Overcome Linux Kernel Vulnerability Challenges
This technical article details the exploitation of CVE-2024-50264, a challenging Linux kernel vulnerability that won the Pwnie Award 2025 fo
Comments
Sign in to join the conversation.
No comments yet. Be the first.
