Symantec
symantec
571 CVEs • 247 products
Products (247)
Click to collapseToggle
Products (247)
Click to collapse
CVEs (571)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Symantec 3Veritas Netbackup Client Veritas Netbackup Enterprise ServerVeritas Netbackup ServerApr 23, 2026 Dec 14, 2006 N/A· v4 N/A· v3 10.0 HIGH· v2 The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arb...Show more |
1Symantec 1Livestate Agent For Windows Apr 23, 2026 Dec 6, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elev...Show more |
Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay. |
1Symantec 2Client Security Norton AntivirusApr 23, 2026 Oct 23, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified...Show more |
1Symantec 4Automated Support Assistant Norton AntivirusNorton Internet Security+1 moreApr 23, 2026 Oct 19, 2006 N/A· v4 N/A· v3 2.6 LOW· v2 Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtai...Show more |
1Symantec 4Automated Support Assistant Norton AntivirusNorton Internet Security+1 moreApr 23, 2026 Oct 19, 2006 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cau...Show more |
1Symantec 2Naveng Driver Navex15 DriverApr 23, 2026 Oct 10, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system ad...Show more |
1Symantec 1Sygate Network Access Control Apr 16, 2026 Sep 26, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Symantec Sygate NAC allows physically proximate attackers to bypass control methods and join a local network by selecting a forged MAC address associated with an exception rule that (1) permits all non-Windows devices or...Show more |
1Symantec 7Client Security Host IdsNorton Antivirus+4 moreApr 16, 2026 Sep 19, 2006 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3...Show more |
1Symantec 2Client Security Norton AntivirusApr 16, 2026 Sep 14, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified v...Show more |
1Symantec 2Client Security Norton AntivirusApr 16, 2026 Sep 14, 2006 N/A· v4 N/A· v3 7.2 HIGH· v2 Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection an...Show more |
The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has...Show more |
1Symantec 1Enterprise Security Manager Apr 16, 2026 Aug 23, 2006 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The manager server in Symantec Enterprise Security Manager (ESM) 6 and 6.5.x allows remote attackers to cause a denial of service (hang) via a malformed ESM agent request. |
Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegResto...Show more |
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts". |
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain file...Show more |
1Symantec 2On Demand Agent On Demand ProtectionApr 16, 2026 Aug 5, 2006 N/A· v4 N/A· v3 2.1 LOW· v2 Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the Virtual Desktop module in Symantec On-Demand Protection (SODP) before 2.6 Build 2233, do not properly encrypt files that are subject to policy-based auto...Show more |
Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag. |
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the...Show more |
Symantec pcAnywhere 12.5 uses weak default permissions for the "Symantec\pcAnywhere\Hosts" folder, which allows local users to gain privileges by inserting a superuser .cif (aka caller or CallerID) file into the folder,...Show more |