← Back

Symantec

symantec

571 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Web Gateway
web_gateway
Mail Security
mail_security
Pcanywhere
pcanywhere
Antivirus
antivirus
Norton 360
norton_360
Norton Ghost
norton_ghost
Csapi
csapi
Velociraptor
velociraptor
Web Security
web_security
Pgp Desktop
pgp_desktop
Ngc
ngc
System Center
system_center
Im Manager
im_manager
Liveupdate
liveupdate
Backup Exec
backup_exec
Discovery
discovery
Scan Engine
scan_engine
Norton Family
norton_family

CVEs (571)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Web Gateway
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" is...Show more
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.Show less
1Symantec
2Backupexec System Recovery
System Recovery
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working director...Show more
Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory.Show less
1Symantec
1Message Filter
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.Show less
1Symantec
1Message Filter
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Symantec
1Message Filter
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.
1Symantec
1Message Filter
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via u...Show more
Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors.Show less
1Symantec
1Liveupdate Administrator
Apr 29, 2026
Jun 22, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
1Symantec
1Endpoint Protection
Apr 29, 2026
May 24, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outa...Show more
The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood of packets that triggers automated blocking of network traffic.Show less
1Symantec
1Endpoint Protection
Apr 29, 2026
May 23, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation...Show more
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.Show less
1Symantec
1Endpoint Protection
Apr 29, 2026
May 23, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to delete files via unspecified vectors.
1Symantec
2Endpoint Protection
Network Access Control
Apr 29, 2026
May 23, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a d...Show more
Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.Show less
1Symantec
1Web Gateway
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vecto...Show more
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors.Show less
1Symantec
1Web Gateway
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors.
1Symantec
1Web Gateway
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) includi...Show more
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.Show less