← Back

Symantec

symantec

571 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Web Gateway
web_gateway
Mail Security
mail_security
Pcanywhere
pcanywhere
Antivirus
antivirus
Norton 360
norton_360
Norton Ghost
norton_ghost
Csapi
csapi
Velociraptor
velociraptor
Web Security
web_security
Pgp Desktop
pgp_desktop
Ngc
ngc
System Center
system_center
Im Manager
im_manager
Liveupdate
liveupdate
Backup Exec
backup_exec
Discovery
discovery
Scan Engine
scan_engine
Norton Family
norton_family

CVEs (571)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Web Isolation
Nov 21, 2024
Oct 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using craft...Show more
Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code into the website's rendered copy running inside the end user's web browser. It does not allow injecting code into the real (isolated) copy of the website running on the WI Threat Isolation Engine.Show less
1Symantec
1Messaging Gateway
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a we...Show more
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.Show less
1Symantec
1Messaging Gateway
Nov 21, 2024
Sep 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in...Show more
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.Show less
1Symantec
1Norton Password Manager
Nov 21, 2024
Aug 29, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data...Show more
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.Show less
1Symantec
2Norton Power Eraser
Symdiag
Nov 21, 2024
Aug 22, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution a...Show more
Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application.Show less
1Symantec
1Norton Utilities
Nov 21, 2024
Aug 22, 2018
N/A· v4
6.0 MEDIUM· v3
4.4 MEDIUM· v2
Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicio...Show more
Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application.Show less
1Symantec
1Encryption Management Server
Nov 21, 2024
Aug 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a p...Show more
The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.Show less
1Symantec
1Inventory
Nov 21, 2024
Jul 25, 2018
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated...Show more
The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.Show less
1Symantec
1Norton App Lock
Nov 21, 2024
Jul 16, 2018
N/A· v4
6.2 MEDIUM· v3
7.2 HIGH· v2
Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the i...Show more
Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.Show less
1Symantec
1Endpoint Protection
Nov 21, 2024
Jun 20, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are no...Show more
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.Show less
1Symantec
1Endpoint Protection
Nov 21, 2024
Jun 20, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of...Show more
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events.Show less
1Symantec
1Norton App Lock
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.2 MEDIUM· v3
7.2 HIGH· v2
Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowin...Show more
Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.Show less
1Symantec
1Norton Core Firmware
Nov 21, 2024
Apr 30, 2018
N/A· v4
8.0 HIGH· v3
8.3 HIGH· v2
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is execution of arbitrary commands on the host system via vulnerable software.
1Symantec
1Management Console
Nov 21, 2024
Apr 16, 2018
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser....Show more
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.Show less
1Symantec
1Endpoint Protection
Nov 21, 2024
Apr 16, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV f...Show more
Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV files. Prior to 14.0 MP1 and 12.1 RU6 MP7, the potential exists for file metadata to be interpreted and evaluated as a formula. Successful exploitation of an attack of this type requires considerable direct user-interaction from the user exporting and then opening the log files on the intended target client.Show less
1Symantec
1Endpoint Protection
Nov 21, 2024
Apr 16, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin use...Show more
A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin user would need to be able to save an executable file to disk and then be able to successfully run that file. If properly constructed, the file could access the driver interface and potentially manipulate certain system calls. On all 32-bit systems and in most cases on 64-bit systems, this will result in a denial of service that will crash the system. In very narrow circumstances, and on 64-bit systems only, this could allow the user to run arbitrary code on the local machine with kernel-level privileges. This could result in a non-privileged user gaining privileged access on the local machine.Show less
1Symantec
1Norton App Lock
Nov 21, 2024
Mar 26, 2018
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, th...Show more
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access.Show less
1Symantec
4Backup Exec System Recovery
Norton 360Norton Ghost+1 more
Nov 21, 2024
Feb 19, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a deni...Show more
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.Show less
1Symantec
1Altiris Deployment Solution
Nov 21, 2024
Feb 19, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
DBManager in Symantec Altiris Deployment Solution 6.9.x before DS 6.9 SP4 allows remote attackers to cause a denial of service via a crafted request.
1Symantec
1Reporter
Nov 21, 2024
Jan 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password...Show more
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.Show less