Vulnerabilities > Bitdefender > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-07 CVE-2021-4198 NULL Pointer Dereference vulnerability in Bitdefender products
A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files.
local
low complexity
bitdefender CWE-476
3.6
2021-11-09 CVE-2021-3641 Link Following vulnerability in Bitdefender Gravityzone
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service.
local
low complexity
bitdefender CWE-59
3.6
2021-05-18 CVE-2020-15279 Unspecified vulnerability in Bitdefender Endpoint Security Tools 6.6.18.261
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths.
local
low complexity
bitdefender
3.3
2020-12-17 CVE-2020-15292 Improper Input Validation vulnerability in Bitdefender Hypervisor Introspection
Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it could cause DoS due to integer-overflor (IntPeGetDirectory), TOCTOU (IntPeParseUnwindData) or insufficient validations.
local
low complexity
bitdefender CWE-20
2.1
2020-12-17 CVE-2020-15293 Improper Input Validation vulnerability in Bitdefender Hypervisor Introspection 1.132.2
Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions.
local
low complexity
bitdefender CWE-20
2.1
2020-06-05 CVE-2020-8103 Link Following vulnerability in Bitdefender Antivirus 2020 1.0.15.138/1.0.17/1.0.17.169
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location.
local
low complexity
bitdefender CWE-59
3.6
2020-01-30 CVE-2020-8092 Improper Privilege Management vulnerability in Bitdefender Antivirus
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud.
local
low complexity
bitdefender CWE-269
2.1
2020-01-27 CVE-2019-17103 Incorrect Default Permissions vulnerability in Bitdefender Antivirus
An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read protected directories.
local
low complexity
bitdefender CWE-276
2.1
2019-05-24 CVE-2018-18058 Divide By Zero vulnerability in Bitdefender Scan Engines
An issue was discovered in Bitdefender Engines before 7.76662.
network
high complexity
bitdefender CWE-369
2.6
2019-05-24 CVE-2018-18059 Out-of-bounds Read vulnerability in Bitdefender Scan Engines 7.76662
An issue was discovered in Bitdefender Engines before 7.76675.
network
high complexity
bitdefender CWE-125
2.6