← Back

Symantec

symantec

571 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Web Gateway
web_gateway
Mail Security
mail_security
Pcanywhere
pcanywhere
Antivirus
antivirus
Norton 360
norton_360
Norton Ghost
norton_ghost
Csapi
csapi
Velociraptor
velociraptor
Web Security
web_security
Pgp Desktop
pgp_desktop
Ngc
ngc
System Center
system_center
Im Manager
im_manager
Liveupdate
liveupdate
Backup Exec
backup_exec
Discovery
discovery
Scan Engine
scan_engine
Norton Family
norton_family

CVEs (571)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
3Veritas Netbackup Client
Veritas Netbackup Enterprise ServerVeritas Netbackup Server
Apr 23, 2026
Dec 14, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arb...Show more
The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.Show less
1Symantec
1Livestate Agent For Windows
Apr 23, 2026
Dec 6, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elev...Show more
Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerabilityShow less
1Symantec
1Mail Security
Apr 23, 2026
Oct 26, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.
1Symantec
2Client Security
Norton Antivirus
Apr 23, 2026
Oct 23, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified...Show more
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.Show less
1Symantec
4Automated Support Assistant
Norton AntivirusNorton Internet Security+1 more
Apr 23, 2026
Oct 19, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtai...Show more
Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via unspecified vectors.Show less
1Symantec
4Automated Support Assistant
Norton AntivirusNorton Internet Security+1 more
Apr 23, 2026
Oct 19, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cau...Show more
Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.Show less
1Symantec
2Naveng Driver
Navex15 Driver
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system ad...Show more
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.Show less
1Symantec
1Sygate Network Access Control
Apr 16, 2026
Sep 26, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Symantec Sygate NAC allows physically proximate attackers to bypass control methods and join a local network by selecting a forged MAC address associated with an exception rule that (1) permits all non-Windows devices or...Show more
Symantec Sygate NAC allows physically proximate attackers to bypass control methods and join a local network by selecting a forged MAC address associated with an exception rule that (1) permits all non-Windows devices or (2) whitelists certain sets of Organizationally Unique Identifiers (OUIs).Show less
1Symantec
7Client Security
Host IdsNorton Antivirus+4 more
Apr 16, 2026
Sep 19, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3...Show more
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data.Show less
1Symantec
2Client Security
Norton Antivirus
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified v...Show more
Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notification messages, a different vector than CVE-2006-3454, a "second format string vulnerability" as found by the vendor.Show less
1Symantec
2Client Security
Norton Antivirus
Apr 16, 2026
Sep 14, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection an...Show more
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.Show less
1Symantec
1Gateway Security
Apr 16, 2026
Sep 6, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has...Show more
The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has stated that the default configuration does not proxy DNS queries received on the external interfaceShow less
1Symantec
1Enterprise Security Manager
Apr 16, 2026
Aug 23, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The manager server in Symantec Enterprise Security Manager (ESM) 6 and 6.5.x allows remote attackers to cause a denial of service (hang) via a malformed ESM agent request.
1Symantec
1Norton Personal Firewall
Apr 16, 2026
Aug 21, 2006
N/A· v4
N/A· v3
3.6 LOW· v2
Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegResto...Show more
Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegRestoreKey to modify HKLM\SOFTWARE\Symantec\CCPD\SuiteOwners, as demonstrated using NISProd.dll. NOTE: in most cases, this attack would not cross privilege boundaries, because modifying the SuiteOwners key requires administrative privileges. However, this issue is a vulnerability because the product's functionality is intended to protect against privileged actions such as this.Show less
1Symantec
1Brightmail Antispam
Apr 16, 2026
Aug 7, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts".
1Symantec
1Brightmail Antispam
Apr 16, 2026
Aug 7, 2006
N/A· v4
N/A· v3
7.6 HIGH· v2
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain file...Show more
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests.Show less
1Symantec
2On Demand Agent
On Demand Protection
Apr 16, 2026
Aug 5, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the Virtual Desktop module in Symantec On-Demand Protection (SODP) before 2.6 Build 2233, do not properly encrypt files that are subject to policy-based auto...Show more
Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the Virtual Desktop module in Symantec On-Demand Protection (SODP) before 2.6 Build 2233, do not properly encrypt files that are subject to policy-based automatic encryption, which might allow local users to read sensitive data via an unspecified decryption method.Show less
1Symantec
1Pcanywhere
Apr 16, 2026
Jul 24, 2006
N/A· v4
N/A· v3
3.6 LOW· v2
Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag.
1Symantec
1Pcanywhere
Apr 16, 2026
Jul 24, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the...Show more
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft Asterwin.Show less
1Symantec
1Pcanywhere
Apr 16, 2026
Jul 24, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Symantec pcAnywhere 12.5 uses weak default permissions for the "Symantec\pcAnywhere\Hosts" folder, which allows local users to gain privileges by inserting a superuser .cif (aka caller or CallerID) file into the folder,...Show more
Symantec pcAnywhere 12.5 uses weak default permissions for the "Symantec\pcAnywhere\Hosts" folder, which allows local users to gain privileges by inserting a superuser .cif (aka caller or CallerID) file into the folder, and then using a pcAnywhere client to login as a local administrator.Show less