Carbon Black
by Carbonblack
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-9568 | Cri | 0.64 | 9.8 | 0.02 | Feb 19, 2018 | A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions. | ||
| CVE-2016-9570 | Hig | 0.49 | 7.5 | 0.01 | Feb 12, 2018 | cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe. | ||
| CVE-2018-10407 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2018 | An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by… | ||
| CVE-2016-9569 | Med | 0.29 | 4.4 | 0.00 | Feb 12, 2018 | The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430028 IOCTL call. | ||
| CVE-2014-1615 | 0.00 | — | 0.01 | Apr 22, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to… |
- risk 0.64cvss 9.8epss 0.02
A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
- risk 0.49cvss 7.5epss 0.01
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by…
- risk 0.29cvss 4.4epss 0.00
The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430028 IOCTL call.
- CVE-2014-1615Apr 22, 2014risk 0.00cvss —epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to…