VYPR

Vendor CVEs

Symantec

All CVEs

799 total · sorted by risk
  • CVE-2017-8856CriMay 9, 2017
    risk 0.64cvss 9.8epss 0.04

    In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the 'bprd' process.

  • CVE-2017-6409CriMar 2, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access.

  • CVE-2016-7399CriJan 4, 2017
    risk 0.64cvss 9.8epss 0.05

    scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.

  • CVE-2016-2208CriMay 19, 2016
    risk 0.64cvss 9.1epss 0.19

    The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.

  • CVE-2015-6552CriMay 7, 2016
    risk 0.64cvss 9.8epss 0.02

    The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2…

  • CVE-2015-6550CriMay 7, 2016
    risk 0.64cvss 9.8epss 0.03

    bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary…

  • CVE-2013-5017CriJun 18, 2014
    risk 0.64cvss 9.8epss 0.07

    SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2001-1125CriOct 5, 2001
    risk 0.64cvss 9.8epss 0.02

    Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.

  • CVE-2024-23617CriJan 26, 2024
    risk 0.63cvss 9.6epss 0.02

    A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.

  • CVE-2022-36990CriJul 28, 2022
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to…

  • CVE-2022-36949CriJul 27, 2022
    risk 0.60cvss 9.3epss 0.00

    In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2020-36169CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create…

  • CVE-2020-36168CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas Resiliency Platform 3.4 and 3.5. It leverages OpenSSL on Windows systems when using the Managed Host addon. On start-up, it loads the OpenSSL library. This library may attempt to load the openssl.cnf configuration file, which does not exist. By…

  • CVE-2020-36167CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from the Installation folder. This library in turn attempts to load the /usr/local/ssl/openssl.cnf…

  • CVE-2020-36166CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the…

  • CVE-2020-36165CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. By default, on Windows systems,…

  • CVE-2020-36164CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\)…

  • CVE-2020-36163CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create…

  • CVE-2020-36162CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas CloudPoint before 8.3.0.1+hotfix. The CloudPoint Windows Agent leverages OpenSSL. This OpenSSL library attempts to load the \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems users can create…

  • CVE-2020-36160CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can…

  • CVE-2017-6328HigAug 11, 2017
    risk 0.60cvss 8.8epss 0.02

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user…

  • CVE-2022-42308CriOct 3, 2022
    risk 0.59cvss 9.0epss 0.00

    An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.

  • CVE-2022-42302CriOct 3, 2022
    risk 0.59cvss 9.0epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.

  • CVE-2022-36956CriJul 27, 2022
    risk 0.59cvss 9.0epss 0.01

    In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.

  • CVE-2021-46825CriJul 7, 2022
    risk 0.59cvss 9.1epss 0.02

    Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the…

  • CVE-2016-3646HigJun 30, 2016
    risk 0.59cvss 8.4epss 0.18

    The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec…

  • CVE-2016-3644HigJun 30, 2016
    risk 0.59cvss 8.4epss 0.18

    The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec…

  • CVE-2016-2207HigJun 30, 2016
    risk 0.59cvss 8.4epss 0.18

    The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec…

  • CVE-2015-8151CriFeb 18, 2016
    risk 0.59cvss 9.1epss 0.02

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.

  • CVE-2019-14418HigJul 29, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use…

  • CVE-2016-5313HigApr 12, 2017
    risk 0.58cvss 8.8epss 0.05

    Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

  • CVE-2015-8154HigMar 18, 2016
    risk 0.58cvss 8.8epss 0.05

    The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions."

  • CVE-2026-44925HigMay 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's…

  • CVE-2022-25628HigDec 16, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4

  • CVE-2022-46413HigDec 4, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.

  • CVE-2022-46412HigDec 4, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.

  • CVE-2022-46411HigDec 4, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.

  • CVE-2022-46410HigDec 4, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.

  • CVE-2022-36993HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on…

  • CVE-2022-36989HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on…

  • CVE-2020-36161HigJan 6, 2021
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a directory at the configuration file locations. When the Windows system restarts, a…

  • CVE-2018-12243HigSep 19, 2018
    risk 0.57cvss 8.8epss 0.01

    The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI…

  • CVE-2018-5237HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.02

    Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.

  • CVE-2016-9092HigMay 11, 2017
    risk 0.57cvss 8.8epss 0.01

    The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the…

  • CVE-2017-6407HigMar 2, 2017
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.

  • CVE-2017-6406HigMar 2, 2017
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.

  • CVE-2017-6400HigMar 2, 2017
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on NetBackup Server and Client can occur (on the local system).

  • CVE-2017-6399HigMar 2, 2017
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.

  • CVE-2016-3650HigJun 30, 2016
    risk 0.57cvss 8.8epss 0.01

    Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.

  • CVE-2016-3648HigJun 30, 2016
    risk 0.57cvss 8.8epss 0.02

    Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts, by entering data into the…

Page 2 of 16