Carbonblack develops endpoint detection and response (EDR) and threat-intelligence products that operate across enterprise security infrastructure, with its vulnerability footprint centered on the core Carbon Black platform. The observed weakness classes—including out-of-bounds reads, cross-site request forgery, cryptographic-signature verification flaws, and NULL-pointer dereferences—span both memory-safety and authentication-boundary concerns typical of security-focused software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carbonblack over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9568CRITICAL A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions. | Feb 19, 2018 | 9.8 | 30 | NO | NO |
CVE-2016-9570HIGH cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to th | Feb 12, 2018 | 7.5 | 23 | NO | NO |
CVE-2014-1615MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add | Apr 22, 2014 | 6.8 | 21 | NO | NO |
CVE-2018-10407MEDIUM An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the | Jun 13, 2018 | 5.5 | 17 | NO | NO |
CVE-2016-9569MEDIUM The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter | Feb 12, 2018 | 4.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carbonblack.
Media articles that mention a CVE ID that affects a product developed by Carbonblack — matched by CVE ID, not by vendor name.