VYPR
Vendor

Webroot Software

Products
15
CVEs
27
Across products
34
Status
Private

Products

15

Recent CVEs

27
View all 27 CVEs →
  • CVE-2024-7826CriOct 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

  • CVE-2024-7825CriOct 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

  • CVE-2024-7824CriOct 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

  • CVE-2020-5754CriJun 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

  • CVE-2018-4012CriJan 3, 2019
    risk 0.59cvss 9.0epss 0.03

    An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a…

  • CVE-2018-4015HigDec 18, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote…

  • CVE-2023-7241HigMay 1, 2024
    risk 0.51cvss 7.9epss 0.00

    Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.

  • CVE-2020-5755HigJun 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.

  • CVE-2018-16962HigSep 12, 2018
    risk 0.51cvss 7.8epss 0.01

    Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.

  • CVE-2021-40425MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability…

  • CVE-2021-40424MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability…

  • CVE-2023-29820MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and…

  • CVE-2023-29819MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.

  • CVE-2023-29818MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.

  • CVE-2014-5741Sep 9, 2014
    risk 0.00cvss —epss 0.00

    The Security - Complete (aka com.webroot.security.complete) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2014-5740Sep 9, 2014
    risk 0.00cvss —epss 0.00

    The Security - Free (aka com.webroot.security) application 3.6.0.6610 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2010-5183Aug 25, 2012
    risk 0.00cvss —epss 0.00

    Race condition in Webroot Internet Security Essentials 6.1.0.145 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain…

  • CVE-2010-5173Aug 25, 2012
    risk 0.00cvss —epss 0.00

    Race condition in PC Tools Firewall Plus 6.0.0.88 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory…

  • CVE-2006-6959Jan 29, 2007
    risk 0.00cvss —epss 0.00

    WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.

  • CVE-2006-6961Jan 29, 2007
    risk 0.00cvss —epss 0.01

    WebRoot Spy Sweeper 4.5.9 and earlier does not detect malware based on file contents, which allows remote attackers to bypass malware detection by changing a file's name.