VYPR
Vendor

Webroot Software

Products
16
CVEs
27
Across products
37
Status
Private

Products

16

Recent CVEs

27
View all 27 CVEs →
  • CVE-2024-7826CriOct 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

  • CVE-2024-7825CriOct 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

  • CVE-2024-7824CriOct 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

  • CVE-2020-5754CriJun 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

  • CVE-2018-4012CriJan 3, 2019
    risk 0.59cvss 9.0epss 0.03

    An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a…

  • CVE-2018-4015HigDec 18, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote…

  • CVE-2023-7241HigMay 1, 2024
    risk 0.51cvss 7.9epss 0.00

    Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.

  • CVE-2020-5755HigJun 15, 2020
    risk 0.51cvss 7.8epss 0.00

    Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.

  • CVE-2018-16962HigSep 12, 2018
    risk 0.51cvss 7.8epss 0.01

    Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.

  • CVE-2021-40425MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability…

  • CVE-2021-40424MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability…

  • CVE-2023-29820MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and…

  • CVE-2023-29819MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.

  • CVE-2023-29818MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.

  • CVE-2014-5741Sep 9, 2014
    risk 0.00cvss epss 0.00

    The Security - Complete (aka com.webroot.security.complete) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2014-5740Sep 9, 2014
    risk 0.00cvss epss 0.00

    The Security - Free (aka com.webroot.security) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2010-5183Aug 25, 2012
    risk 0.00cvss epss 0.00

    Race condition in Webroot Internet Security Essentials 6.1.0.145 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain…

  • CVE-2010-5173Aug 25, 2012
    risk 0.00cvss epss 0.00

    Race condition in PC Tools Firewall Plus 6.0.0.88 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory…

  • CVE-2006-6959Jan 29, 2007
    risk 0.00cvss epss 0.00

    WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.

  • CVE-2006-6960Jan 29, 2007
    risk 0.00cvss epss 0.01

    The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files with (1) RAR, (2) GZ, (3) TAR, (4) CAB, or (5) ACE compression.