Skip to main content

Vendor/product archive

bitdefender / gravityzone CVEs

Beta · best-effort

16 CVEs tagged to bitdefender / gravityzone5 Critical, 5 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-2244

Published Apr 4, 2025

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without val…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2243

Published Apr 4, 2025

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests.…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-6980

Published Jul 31, 2024

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4177

Published Jun 6, 2024

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2830

Published Sep 5, 2022

Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environmen…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3960

Published Dec 16, 2021

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3959

Published Dec 16, 2021

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay serve…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3641

Published Nov 9, 2021

Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to ca…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3823

Published Oct 28, 2021

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8931

Published Oct 30, 2018

Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8955

Published Oct 24, 2018

The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5350

Published Aug 19, 2014

Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1