Symantec
symantec
571 CVEs • 247 products
Products (247)
Click to collapseToggle
Products (247)
Click to collapse
CVEs (571)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors. |
1Symantec 1Endpoint Protection Manager May 6, 2026 Aug 1, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown vectors. |
1Symantec 1Endpoint Protection Manager May 6, 2026 Aug 1, 2015 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafte...Show more |
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative sessi...Show more |
Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrat...Show more |
Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspeci...Show more |
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain p...Show more |
Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vectors. |
1Symantec 2Encryption Management Server Pgp Universal ServerMay 6, 2026 Feb 1, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action...Show more |
1Symantec 2Encryption Management Server Pgp Universal ServerMay 6, 2026 Feb 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID valu...Show more |
2Broadcom Symantec2Data Center Security Symantec Critical System ProtectionMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Po...Show more |
2Broadcom Symantec2Data Center Security Symantec Critical System ProtectionMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated...Show more |
2Broadcom Symantec2Data Center Security Symantec Critical System ProtectionMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security:...Show more |
2Broadcom Symantec2Data Center Security Symantec Critical System ProtectionMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 6.5 MEDIUM· v2 SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenti...Show more |
2Broadcom Symantec2Data Center Security Symantec Critical System ProtectionMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenti...Show more |
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors. |
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts. |
1Symantec 1Endpoint Protection Manager May 6, 2026 Nov 7, 2014 N/A· v4 N/A· v3 6.1 MEDIUM· v2 ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors. |
1Symantec 1Endpoint Protection Manager May 6, 2026 Nov 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecifie...Show more |
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity de...Show more |