VYPR

Vendor CVEs

Symantec

All CVEs

799 total · sorted by risk
  • CVE-2019-12750HigJul 31, 2019
    risk 0.51cvss 7.8epss 0.01

    Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt…

  • CVE-2019-9703HigJul 1, 2019
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.

  • CVE-2019-9702HigJul 1, 2019
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.

  • CVE-2018-18367HigApr 25, 2019
    risk 0.51cvss 7.8epss 0.02

    Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a…

  • CVE-2018-18369HigApr 25, 2019
    risk 0.51cvss 7.8epss 0.02

    Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call…

  • CVE-2019-9694HigApr 10, 2019
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from…

  • CVE-2018-12245HigNov 29, 2018
    risk 0.51cvss 7.8epss 0.01

    Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of…

  • CVE-2018-12238HigNov 29, 2018
    risk 0.51cvss 7.8epss 0.00

    Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be…

  • CVE-2018-5238HigAug 22, 2018
    risk 0.51cvss 7.8epss 0.02

    Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.…

  • CVE-2016-9094HigApr 16, 2018
    risk 0.51cvss 7.8epss 0.01

    Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV files. Prior to 14.0 MP1 and 12.1 RU6 MP7, the potential…

  • CVE-2017-13681HigNov 6, 2017
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection prior to SEP 12.1 RU6 MP9 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. In the circumstances of this…

  • CVE-2017-13674HigSep 1, 2017
    risk 0.51cvss 7.8epss 0.00

    Symantec ProxyClient 3.4 for Windows is susceptible to a privilege escalation vulnerability. A malicious local Windows user can, under certain circumstances, exploit this vulnerability to escalate their privileges on the system and execute arbitrary code with LocalSystem…

  • CVE-2017-6329HigAug 21, 2017
    risk 0.51cvss 7.8epss 0.01

    Symantec VIP Access for Desktop prior to 2.2.4 can be susceptible to a DLL Pre-Loading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is…

  • CVE-2016-9100HigMay 11, 2017
    risk 0.51cvss 7.8epss 0.00

    Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability. An attacker with local access to the…

  • CVE-2017-7444HigApr 5, 2017
    risk 0.51cvss 7.8epss 0.01

    In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.

  • CVE-2017-6401HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bpcd and bpnbat.

  • CVE-2016-2210HigJun 30, 2016
    risk 0.51cvss 7.3epss 0.11

    Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint…

  • CVE-2015-8156HigMay 14, 2016
    risk 0.51cvss 7.8epss 0.00

    Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

  • CVE-2015-8150HigFeb 18, 2016
    risk 0.51cvss 7.8epss 0.00

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

  • CVE-2013-1609HigMar 26, 2013
    risk 0.51cvss 7.8epss 0.00

    Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.

  • CVE-2008-6828HigJun 8, 2009
    risk 0.51cvss 7.8epss 0.00

    Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.

  • CVE-2008-6827HigJun 8, 2009
    risk 0.51cvss 7.8epss 0.01

    The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite…

  • CVE-2024-33672HigApr 26, 2024
    risk 0.50cvss 7.7epss 0.00

    An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.

  • CVE-2024-33671HigApr 26, 2024
    risk 0.50cvss 7.7epss 0.00

    An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.

  • CVE-2022-36984HigJul 28, 2022
    risk 0.50cvss 7.7epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service…

  • CVE-2016-5312MedApr 14, 2017
    risk 0.50cvss 6.5epss 0.54

    Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.

  • CVE-2016-3647HigJun 30, 2016
    risk 0.50cvss 7.7epss 0.02

    Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet hosts, via a crafted request.

  • CVE-2015-8799HigJun 8, 2016
    risk 0.50cvss 7.6epss 0.05

    Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection…

  • CVE-2004-0079HigNov 23, 2004
    risk 0.50cvss 7.5epss 0.10

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

  • CVE-2022-37017HigDec 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly…

  • CVE-2022-45461HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.

  • CVE-2020-12593HigNov 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2020-5839HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2020-12877HigMay 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.

  • CVE-2020-12876HigMay 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.

  • CVE-2018-18365HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic.

  • CVE-2018-5243HigAug 20, 2018
    risk 0.49cvss 7.5epss 0.02

    The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its…

  • CVE-2017-13677HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.05

    Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service through management console application crashes.

  • CVE-2017-6331HigNov 6, 2017
    risk 0.49cvss 7.1epss 0.02

    Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.

  • CVE-2017-6405HigMar 2, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Hostname-based security is open to DNS spoofing.

  • CVE-2015-8149HigFeb 18, 2016
    risk 0.49cvss 7.5epss 0.02

    The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests.

  • CVE-2015-8148HigFeb 18, 2016
    risk 0.49cvss 7.5epss 0.02

    The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.

  • CVE-2002-0485HigAug 12, 2002
    risk 0.49cvss 7.5epss 0.01

    Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.

  • CVE-2019-18379HigDec 11, 2019
    risk 0.48cvss 7.3epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through…

  • CVE-2018-18364HigFeb 8, 2019
    risk 0.48cvss 7.3epss 0.01

    Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1 may be susceptible to a DLL hijacking vulnerability, which is a type of issue whereby a potential attacker attempts to execute unexpected code on your machine. This occurs via placement of a potentially foreign file…

  • CVE-2016-10258MedApr 11, 2018
    risk 0.48cvss 6.8epss 0.05

    Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and…

  • CVE-2017-6324HigJun 26, 2017
    risk 0.48cvss 7.3epss 0.01

    The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'bypass' of the disarm…

  • CVE-2016-5304MedJun 30, 2016
    risk 0.48cvss 6.8epss 0.04

    Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2015-8800HigJun 8, 2016
    risk 0.48cvss 7.3epss 0.01

    Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced…

  • CVE-2024-27283HigFeb 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to arbitrary locations on the server on which the application is installed.

Page 4 of 16