Vulnerabilities > Malwarebytes > Malwarebytes

DATE CVE VULNERABILITY TITLE RISK
2023-06-30 CVE-2023-29147 Unspecified vulnerability in Malwarebytes Endpoint Detection and Response and Malwarebytes
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.
local
low complexity
malwarebytes
5.5
2023-06-30 CVE-2023-29145 Unspecified vulnerability in Malwarebytes Endpoint Detection and Response and Malwarebytes
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution.
local
low complexity
malwarebytes
7.8
2023-03-23 CVE-2023-26088 Link Following vulnerability in Malwarebytes
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system.
local
low complexity
malwarebytes CWE-59
7.8
2021-01-15 CVE-2020-25533 Race Condition vulnerability in Malwarebytes
An issue was discovered in Malwarebytes before 4.0 on macOS.
local
high complexity
malwarebytes CWE-362
7.0
2020-12-22 CVE-2020-28641 Link Following vulnerability in Malwarebytes Endpoint Protection and Malwarebytes
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
local
low complexity
malwarebytes CWE-59
7.1
2018-01-08 CVE-2018-5279 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5278 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5277 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5276 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5275 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020.
local
low complexity
malwarebytes CWE-20
7.8