← Back

Symantec

symantec

571 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Web Gateway
web_gateway
Mail Security
mail_security
Pcanywhere
pcanywhere
Antivirus
antivirus
Norton 360
norton_360
Norton Ghost
norton_ghost
Csapi
csapi
Velociraptor
velociraptor
Web Security
web_security
Pgp Desktop
pgp_desktop
Ngc
ngc
System Center
system_center
Im Manager
im_manager
Liveupdate
liveupdate
Backup Exec
backup_exec
Discovery
discovery
Scan Engine
scan_engine
Norton Family
norton_family

CVEs (571)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
10Scan Engine
Symantec Antivirus Filtering Domino MpeSymantec Antivirus Network Attached Storage+7 more
Apr 23, 2026
Feb 28, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary cod...Show more
Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).Show less
1Symantec
10Scan Engine
Symantec Antivirus ClearswiftSymantec Antivirus Filtering Domino Mpe+7 more
Apr 23, 2026
Feb 28, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a...Show more
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).Show less
1Symantec
1Veritas Storage Foundation
Apr 23, 2026
Feb 21, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the Veritas Enterprise Administrator (VEA) service (aka vxsvc.exe) in Symantec Veritas Storage Foundation 5.0 allows remote attackers to execute arbitrary code via a packet with a crafted va...Show more
Heap-based buffer overflow in the Veritas Enterprise Administrator (VEA) service (aka vxsvc.exe) in Symantec Veritas Storage Foundation 5.0 allows remote attackers to execute arbitrary code via a packet with a crafted value of a certain size field, which is not checked for consistency with the actual buffer size.Show less
1Symantec
1Altiris Notification Server
Apr 23, 2026
Feb 12, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack.
1Symantec
1Ghost Solutions Suite
Apr 23, 2026
Feb 8, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via...Show more
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.Show less
1Symantec
1Backupexec System Recovery
Apr 23, 2026
Feb 7, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upl...Show more
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.Show less
1Symantec
1Backupexec System Recovery
Apr 23, 2026
Nov 29, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to cause a denial of service (CPU and memor...Show more
Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to cause a denial of service (CPU and memory consumption) via a crafted packet to port 5633/tcp, which triggers an infinite loop.Show less
1Symantec
1Backupexec System Recovery
Apr 23, 2026
Nov 29, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a...Show more
The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a crafted packet to port 5633/tcp.Show less
4Activepdf
AutonomyIbm+1 more
6Docconverter
Keyview Export SdkKeyview Filter Sdk+3 more
Apr 23, 2026
Nov 10, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Securi...Show more
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.Show less
4Activepdf
AutonomyIbm+1 more
6Docconverter
Keyview Export SdkKeyview Filter Sdk+3 more
Apr 23, 2026
Nov 10, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and oth...Show more
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.Show less
1Symantec
1Altiris Deployment Solution
Apr 23, 2026
Nov 6, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Aclient in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows local users to gain local System privileges via the "Enable key-based authentication to Deployment server" browser option, a different issue tha...Show more
Aclient in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows local users to gain local System privileges via the "Enable key-based authentication to Deployment server" browser option, a different issue than CVE-2007-4380.Show less
1Symantec
2Norton Antivirus
Norton Internet Security
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writabl...Show more
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.Show less
1Symantec
1Proxysg Firmware
Apr 23, 2026
Nov 3, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is...Show more
Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists.Show less
1Symantec
1Altiris Deployment Solution
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solut...Show more
Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solution." NOTE: this description is based on a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Symantec
13Antivirus Scan Engine
Brightmail AntispamClient Security+10 more
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
1Symantec
13Antivirus Scan Engine
Brightmail AntispamClient Security+10 more
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
1Symantec
1Veritas Backup Exec
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the client in Symantec Veritas Backup Exec for Windows Servers 11d has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability info...Show more
Unspecified vulnerability in the client in Symantec Veritas Backup Exec for Windows Servers 11d has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.Show less
1Symantec
1Norton Internet Security
Apr 23, 2026
Sep 24, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibl...Show more
Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-2007-1793.Show less
1Symantec
1Enterprise Firewall
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid, which allows remote...Show more
The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.Show less
1Symantec
1Altiris Deployment Solution
Apr 23, 2026
Aug 16, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Aclient in Symantec Altiris Deployment Solution 6 before 6.8 SP2 (6.8.378) allows local users to gain local System privileges via the Log File Viewer.