VYPR

Vendor CVEs

Symantec

All CVEs

799 total · sorted by risk
  • CVE-2023-38404HigJul 17, 2023
    risk 0.47cvss 7.2epss 0.01

    The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.

  • CVE-2023-32569HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to…

  • CVE-2023-32568HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with…

  • CVE-2019-18377HigDec 11, 2019
    risk 0.47cvss 7.2epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2019-14417HigJul 29, 2019
    risk 0.47cvss 7.2epss 0.04

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to DNS functionality.

  • CVE-2019-14416HigJul 29, 2019
    risk 0.47cvss 7.2epss 0.04

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script…

  • CVE-2019-9868HigMar 21, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.

  • CVE-2019-9867HigMar 21, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is displayed to an administrator.

  • CVE-2018-12237HigJan 24, 2019
    risk 0.47cvss 7.2epss 0.03

    The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.

  • CVE-2018-18652HigOct 25, 2018
    risk 0.47cvss 7.2epss 0.04

    A remote command execution vulnerability in Veritas NetBackup Appliance before 3.1.2 allows authenticated administrators to execute arbitrary commands as root. This issue was caused by insufficient filtering of user provided input.

  • CVE-2016-9097HigMay 11, 2017
    risk 0.47cvss 7.2epss 0.02

    The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A malicious administrator…

  • CVE-2023-28758HigMar 23, 2023
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.

  • CVE-2022-36997HigJul 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger impacts that include…

  • CVE-2020-5835HigMay 11, 2020
    risk 0.46cvss 7.0epss 0.00

    Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine.

  • CVE-2016-6591HigJan 8, 2020
    risk 0.46cvss 7.1epss 0.00

    A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.

  • CVE-2016-9093HigApr 16, 2018
    risk 0.46cvss 7.0epss 0.00

    A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin user would need to be able to save an executable file to disk…

  • CVE-2017-13676HigSep 28, 2017
    risk 0.46cvss 7.0epss 0.00

    Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will…

  • CVE-2017-6408HigMar 2, 2017
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.

  • CVE-2004-0217HigApr 15, 2004
    risk 0.46cvss 7.0epss 0.00

    The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.

  • CVE-2025-13918MedJan 28, 2026
    risk 0.44cvss 6.7epss 0.00

    Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to…

  • CVE-2024-34404MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a…

  • CVE-2023-23958MedSep 27, 2023
    risk 0.44cvss 6.8epss 0.01

    Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.

  • CVE-2022-25627MedDec 16, 2022
    risk 0.44cvss 6.7epss 0.01

    An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4

  • CVE-2019-12758MedNov 15, 2019
    risk 0.44cvss 6.7epss 0.01

    Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.

  • CVE-2019-9695MedMar 29, 2019
    risk 0.44cvss 6.8epss 0.01

    Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that has the potential of allowing an individual to execute arbitrary commands or code on a target machine or in a target process. Note that this exploit is only…

  • CVE-2018-12239MedNov 29, 2018
    risk 0.44cvss 6.8epss 0.01

    Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be…

  • CVE-2017-15534MedMar 26, 2018
    risk 0.44cvss 6.7epss 0.00

    The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access.

  • CVE-2017-15527MedNov 20, 2017
    risk 0.44cvss 6.8epss 0.01

    Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing…

  • CVE-2017-15526MedNov 13, 2017
    risk 0.44cvss 6.8epss 0.00

    Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-reference issue, which can result in a NullPointerException that can lead to a privilege escalation scenario.

  • CVE-2017-6325MedJun 26, 2017
    risk 0.43cvss 6.6epss 0.03

    The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is caused when an application builds a path to executable code using…

  • CVE-2026-44923MedMay 20, 2026
    risk 0.42cvss 6.5epss 0.00

    SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.

  • CVE-2025-3599MedApr 30, 2025
    risk 0.42cvss 6.5epss 0.00

    Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.

  • CVE-2024-46542MedDec 30, 2024
    risk 0.42cvss 6.5epss 0.01

    Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.

  • CVE-2023-37237MedJun 29, 2023
    risk 0.42cvss 6.5epss 0.01

    In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.

  • CVE-2022-42306MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.

  • CVE-2022-41320MedSep 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that…

  • CVE-2022-37000MedJul 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely…

  • CVE-2022-36999MedJul 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely…

  • CVE-2016-6589MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.02

    A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.

  • CVE-2019-18380MedDec 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.

  • CVE-2019-9697MedAug 30, 2019
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability in the Management Center (MC) REST API 2.0, 2.1, and 2.2 prior to 2.2.2.1 allows a malicious authenticated user to obtain passwords for external backup and CPL policy import servers that they might not otherwise be authorized to access.

  • CVE-2018-18371MedAug 30, 2019
    risk 0.42cvss 6.5epss 0.01

    The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext authentication credentials for…

  • CVE-2018-18366MedApr 25, 2019
    risk 0.42cvss 6.5epss 0.00

    Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory…

  • CVE-2010-0109MedFeb 19, 2018
    risk 0.42cvss 6.5epss 0.01

    DBManager in Symantec Altiris Deployment Solution 6.9.x before DS 6.9 SP4 allows remote attackers to cause a denial of service via a crafted request.

  • CVE-2017-6330MedSep 13, 2017
    risk 0.42cvss 6.5epss 0.01

    Symantec Encryption Desktop before SED 10.4.1MP2 can allow remote attackers to cause a denial of service (resource consumption) via crafted web requests."

  • CVE-2017-6402MedMar 2, 2017
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Denial of service affecting NetBackup server can occur.

  • CVE-2022-36998MedJul 28, 2022
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer…

  • CVE-2022-36994MedJul 28, 2022
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily read files from a…

  • CVE-2020-12875MedMay 14, 2020
    risk 0.41cvss 6.3epss 0.01

    Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating specific parameters within the application.

  • CVE-2019-18381MedDec 5, 2019
    risk 0.41cvss 6.3epss 0.00

    Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was…

Page 5 of 16