Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Antivirus Plus MEDIUM 6.1
CVE-2021-4198

A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus,…

Fix: 7.2.2.92 / 25.5.0.48+
Fix from $1,600 2022-03-07
Antivirus Plus HIGH 7.8
CVE-2020-8107

A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a …

Fix: 24.0.26.136+
Fix from $1,950 2022-02-18
Gravityzone HIGH 7.8
CVE-2021-3960

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone…

Fix: 3.3.8.272+
Fix from $1,950 2021-12-16
Gravityzone HIGH 7.5
CVE-2021-3959

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro…

Fix: 3.3.8.272+
Fix from $1,950 2021-12-16
Endpoint Security Tools CRITICAL 10.0
CVE-2021-3554

Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows…

Fix: 6.6.27.390 / 6.24.1-1+
Fix from $2,300 2021-11-24
Endpoint Security Tools HIGH 7.5
CVE-2021-3552

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to pro…

Fix: 6.2.21.160 / 6.6.27.390+
Fix from $1,950 2021-11-24
Endpoint Security Tools HIGH 7.5
CVE-2021-3553

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpo…

Fix: 6.2.21.160 / 6.6.27.390+
Fix from $1,950 2021-11-24
Gravityzone MEDIUM 6.1
CVE-2021-3641

Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows…

Fix: after 7.1.2.33
Fix from $1,600 2021-11-09
Gravityzone CRITICAL 9.8
CVE-2021-3823

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone…

Fix: 3.3.8.249+
Fix from $2,300 2021-10-28
Endpoint Security Tools HIGH 7.8
CVE-2021-3576

Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT …

Fix: 7.2.1.65 / 25.0.26+
Fix from $1,950 2021-10-28
Endpoint Security Tools HIGH 7.8
CVE-2021-3579

Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security T…

Fix: 7.2.1.65+
Fix from $1,950 2021-10-28
Antivirus Plus HIGH 7.5
CVE-2020-15732

Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to pote…

Fix: 25.0.7.29+
Fix from $1,950 2021-06-22
Endpoint Security Tools MEDIUM 6.6
CVE-2021-3485

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle …

Fix: 6.2.21.155+
Fix from $1,600 2021-05-24
Gravityzone Business Security HIGH 7.8
CVE-2021-3423

Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to lo…

Fix: 6.6.23.329+
Fix from $1,950 2021-05-18
Safepay MEDIUM 5.5
CVE-2020-15734

An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing …

Fix: 25.0.7.29+
Fix from $1,600 2021-04-12
Hypervisor Introspection HIGH 7.0
CVE-2020-15294

Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to t…

Fix: 1.132.2+
Fix from $1,950 2020-12-17
Hypervisor Introspection MEDIUM 5.5
CVE-2020-15292

Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTa…

Fix: 1.132.2+
Fix from $1,600 2020-12-17
Hypervisor Introspection MEDIUM 5.5
CVE-2020-15293

Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input va…

Mitigation only
Fix from $1,600 2020-12-17
Antivirus Plus MEDIUM 6.5
CVE-2020-15733

An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the U…

Fix: 25.0.7.29+
Fix from $1,600 2020-12-14
Update Server CRITICAL 9.1
CVE-2020-15297

Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.29…

Fix: 6.6.20.294+
Fix from $2,300 2020-11-09
Engines HIGH 7.5
CVE-2020-8110

A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-supplied data, which can result …

Fix: after 7.84897
Fix from $1,950 2020-10-02
Engines HIGH 7.5
CVE-2020-8109

A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a …

Fix: after 7.84892
Fix from $1,950 2020-10-01
Endpoint Security HIGH 7.8
CVE-2020-8097

An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivile…

Fix: 6.6.18.261+
Fix from $1,950 2020-08-30
Endpoint Security HIGH 8.8
CVE-2020-8108

Improper Authentication vulnerability in Bitdefender Endpoint Security for Mac allows an unprivileged process to restart the main service and potenti…

Fix: 4.12.80+
Fix from $1,950 2020-08-03
Total Security 2020 HIGH 8.8
CVE-2020-8102

Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web…

Fix: 24.0.20.116+
Fix from $1,950 2020-06-22
Antivirus 2020 HIGH 7.1
CVE-2020-8103

A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined f…

Fix: 1.0.17.178+
Fix from $1,950 2020-06-05
Engines HIGH 7.5
CVE-2020-8100

Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker to trigger a denial of servi…

Fix: 7.84063+
Fix from $1,950 2020-05-15
Antivirus 2020 MEDIUM 6.2
CVE-2020-8099

A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, …

Fix: 1.0.17+
Fix from $1,600 2020-04-21
Antimalware Software Development Kit MEDIUM 5.3
CVE-2020-8096

Untrusted Search Path vulnerability in Bitdefender High-Level Antimalware SDK for Windows allows an attacker to load third party code from a DLL libr…

Fix: 3.0.1.204+
Fix from $1,600 2020-04-07
Total Security 2020 MEDIUM 5.5
CVE-2020-8095

A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial…

Fix: 24.9+
Fix from $1,600 2020-01-30