VYPR

Messaging Gateway

by Symantec

CVEs (37)

  • CVE-2017-6324HigJun 26, 2017
    risk 0.48cvss 7.3epss 0.02

    The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'bypass' of the disarm…

  • CVE-2019-18377HigDec 11, 2019
    risk 0.47cvss 7.2epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2017-6325MedJun 26, 2017
    risk 0.43cvss 6.6epss 0.02

    The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is caused when an application builds a path to executable code using…

  • CVE-2016-5310MedApr 14, 2017
    risk 0.39cvss 5.5epss 0.05

    The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint…

  • CVE-2016-5309MedApr 14, 2017
    risk 0.39cvss 5.5epss 0.07

    The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint…

  • CVE-2022-25630MedDec 9, 2022
    risk 0.38cvss 5.4epss 0.02

    An authenticated user can embed malicious content with XSS into the admin group policy page.

  • CVE-2017-15532MedDec 20, 2017
    risk 0.37cvss 5.7epss 0.01

    Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to…

  • CVE-2022-25629MedDec 9, 2022
    risk 0.35cvss 5.4epss 0.00

    An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).

  • CVE-2019-18378MedDec 11, 2019
    risk 0.31cvss 4.8epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by…

  • CVE-2019-9699MedOct 24, 2019
    risk 0.29cvss 4.5epss 0.00

    Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2012-4347Dec 5, 2012
    risk 0.08cvss —epss 0.59

    Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2)…

  • CVE-2012-3579Aug 29, 2012
    risk 0.06cvss —epss 0.40

    Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.

  • CVE-2012-0308Aug 29, 2012
    risk 0.03cvss —epss 0.02

    Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators.

  • CVE-2014-1648Apr 23, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.

  • CVE-2012-3581Aug 29, 2012
    risk 0.00cvss —epss 0.01

    Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to obtain potentially sensitive information about component versions via unspecified vectors.

  • CVE-2012-3580Aug 29, 2012
    risk 0.00cvss —epss 0.01

    Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface.

  • CVE-2012-0307Aug 29, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web content or (2) e-mail content.

Page 2 of 2