Lucene search

K

Webroot Security Vulnerabilities

cve
cve

CVE-2010-5183

Race condition in Webroot Internet Security Essentials 6.1.0.145 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes ...

6.9AI Score

0.0004EPSS

2012-08-25 09:55 PM
26
cve
cve

CVE-2014-5740

The Security - Free (aka com.webroot.security) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

6AI Score

0.0005EPSS

2014-09-09 10:55 AM
25
cve
cve

CVE-2014-5741

The Security - Complete (aka com.webroot.security.complete) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

6AI Score

0.0005EPSS

2014-09-09 10:55 AM
18
cve
cve

CVE-2018-16962

Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.

7.8CVSS

7.4AI Score

0.0005EPSS

2018-09-12 08:29 PM
456
cve
cve

CVE-2018-4012

An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud serv...

9CVSS

8.4AI Score

0.003EPSS

2019-01-03 11:00 PM
24
cve
cve

CVE-2018-4015

An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server t...

8.1CVSS

7.9AI Score

0.002EPSS

2018-12-18 02:29 PM
34
cve
cve

CVE-2020-5754

Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

9.1CVSS

9AI Score

0.022EPSS

2020-06-15 08:15 PM
33
cve
cve

CVE-2020-5755

Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.

7.8CVSS

7.6AI Score

0.001EPSS

2020-06-15 08:15 PM
23
cve
cve

CVE-2021-40424

An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL Get...

6.5CVSS

6.2AI Score

0.0004EPSS

2022-04-14 08:15 PM
27
cve
cve

CVE-2021-40425

An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL Get...

6.5CVSS

6.2AI Score

0.0004EPSS

2022-04-14 08:15 PM
39
cve
cve

CVE-2023-29818

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.

5.5CVSS

5.3AI Score

0.0004EPSS

2023-05-12 11:15 AM
17
cve
cve

CVE-2023-29819

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.

5.5CVSS

5.2AI Score

0.0004EPSS

2023-05-12 11:15 AM
17
cve
cve

CVE-2023-29820

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and CVE-2023-29819.

5.5CVSS

5AI Score

0.0004EPSS

2023-05-12 11:15 AM
25