← Back

Brightmail Antispam

brightmail_antispam

Vendor: Symantec • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
13Antivirus Scan Engine
Brightmail AntispamClient Security+10 more
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
1Symantec
13Antivirus Scan Engine
Brightmail AntispamClient Security+10 more
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
1Symantec
1Brightmail Antispam
Apr 16, 2026
Aug 7, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts".
1Symantec
1Brightmail Antispam
Apr 16, 2026
Aug 7, 2006
N/A· v4
N/A· v3
7.6 HIGH· v2
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain file...Show more
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests.Show less
1Symantec
1Brightmail Antispam
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages.
1Symantec
1Brightmail Antispam
Apr 16, 2026
Jun 9, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.
1Symantec
11Antivirus Scan Engine
Brightmail AntispamClient Security+8 more
Apr 16, 2026
Feb 8, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
1Symantec
1Brightmail Antispam
Apr 16, 2026
Dec 17, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 cha...Show more
The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters.Show less
1Symantec
1Brightmail Antispam
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.