Lavasoft

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25287

    Adaware Web Companion version 4.8.2078.3950 - 'WCAssistantService' Unquoted Service Path

    Last Modified: Apr 15, 2026
    Published: Feb 04, 2026

    CVE-2020-37102

    Adaware Web Companion 4.9.2159 - 'WCAssistantService' Unquoted Service Path

    Last Modified: Apr 15, 2026
    Published: Feb 03, 2026

    CVE-2025-45095

    Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with write access to the file system could potentially execute arbitrary code with elevated privileges by placing a malicious executable in the unquoted path.

    Last Modified: Apr 15, 2026
    Published: Oct 09, 2025

    CVE-2006-3697

    Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and execute commands (a) via the "open folder" option when no instance of explorer.exe is running, possibly related to the ShellExecute API function; or (b) by overwriting a batch file through the "Save Configuration As" option. NOTE: this might be a vulnerability in Microsoft Windows and explorer.exe instead of the firewall.

    Last Modified: Apr 16, 2026
    Published: Jul 19, 2006
    Items Per Page