Symantec
symantec
571 CVEs • 247 products
Products (247)
Click to collapseToggle
Products (247)
Click to collapse
CVEs (571)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc a...Show more |
1Symantec 1Security Information Manager Apr 16, 2026 Jun 19, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 M4 Macro Library in Symantec Security Information Manager before 4.0.2.29 HOTFIX 1 allows local users to execute arbitrary commands via crafted "rule definitions", which produces dangerous Java code during M4 transformat...Show more |
1Symantec 2Client Security Norton AntivirusApr 16, 2026 May 27, 2006 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors. |
1Symantec 2Enterprise Firewall Gateway SecurityApr 16, 2026 May 12, 2006 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as...Show more |
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the...Show more |
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communication...Show more |
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends ce...Show more |
1Symantec 6Liveupdate Norton AntivirusNorton Internet Security+3 moreApr 16, 2026 Apr 19, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program...Show more |
1Symantec 2Ghost Solutions Suite Norton GhostApr 16, 2026 Mar 19, 2006 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from t...Show more |
1Symantec 2Ghost Solutions Suite Norton GhostApr 16, 2026 Mar 19, 2006 N/A· v4 N/A· v3 3.2 LOW· v2 SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and p...Show more |
1Symantec 2Ghost Solutions Suite Norton GhostApr 16, 2026 Mar 19, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privilege...Show more |
SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication...Show more |
Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and...Show more |
Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages. |
Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors. |
1Symantec 10Enterprise Firewall Firewall Vpn Appliance 100Firewall Vpn Appliance 200+7 moreApr 16, 2026 Nov 23, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attack...Show more |
1Symantec 2Discovery On Command DiscoveryApr 16, 2026 Oct 27, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent...Show more |
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file. |
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this cand...Show more |
Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local he...Show more |