Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown
CVE-2020-5755
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.
0
Attacker Value
Unknown
CVE-2018-4012
Disclosure Date: January 03, 2019 (last updated November 27, 2024)
An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-4015
Disclosure Date: December 18, 2018 (last updated November 27, 2024)
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2018-16962
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.
0
Attacker Value
Unknown
CVE-2014-5740
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Security - Free (aka com.webroot.security) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5741
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Security - Complete (aka com.webroot.security.complete) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2010-5183
Disclosure Date: August 25, 2012 (last updated November 08, 2023)
Race condition in Webroot Internet Security Essentials 6.1.0.145 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute
0
Attacker Value
Unknown
CVE-2006-6959
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.
0
Attacker Value
Unknown
CVE-2006-6961
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
WebRoot Spy Sweeper 4.5.9 and earlier does not detect malware based on file contents, which allows remote attackers to bypass malware detection by changing a file's name.
0
Attacker Value
Unknown
CVE-2006-6960
Disclosure Date: January 29, 2007 (last updated October 04, 2023)
The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files with (1) RAR, (2) GZ, (3) TAR, (4) CAB, or (5) ACE compression.
0