Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2023-29147

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.
Attacker Value
Unknown

CVE-2023-29145

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.
Attacker Value
Unknown

CVE-2020-25502

Disclosure Date: January 20, 2023 (last updated October 08, 2023)
Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which could allow a local attacker to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2022-37015

Disclosure Date: November 08, 2022 (last updated December 22, 2024)
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Attacker Value
Unknown

CVE-2022-28887

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
Attacker Value
Unknown

CVE-2022-28881

Disclosure Date: August 10, 2022 (last updated October 08, 2023)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacker function crashes which leads to scanning engine crash. The exploit can be triggered remotely by an attacker.
Attacker Value
Unknown

CVE-2022-28880

Disclosure Date: August 05, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker.
Attacker Value
Unknown

CVE-2022-28875

Disclosure Date: May 25, 2022 (last updated October 07, 2023)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker.
Attacker Value
Unknown

CVE-2021-40837

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.
Attacker Value
Unknown

CVE-2021-40836

Disclosure Date: December 22, 2021 (last updated October 07, 2023)
A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.