VYPR

Vendor CVEs

Symantec

All CVEs

799 total · sorted by risk
  • CVE-2018-12244MedApr 25, 2019
    risk 0.41cvss 6.3epss 0.01

    SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

  • CVE-2024-47854MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.01

    An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

  • CVE-2023-26788MedApr 10, 2023
    risk 0.40cvss 6.1epss 0.00

    Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.

  • CVE-2023-26789MedApr 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to adequately sanitize special characters. By leveraging this issue, an attacker is able to cause arbitrary HTML and JavaScript code to be executed in a user's…

  • CVE-2022-41319MedSep 23, 2022
    risk 0.40cvss 6.1epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9.7).

  • CVE-2021-30650MedFeb 18, 2022
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering techniques. A successful…

  • CVE-2019-19547MedJan 13, 2020
    risk 0.40cvss 6.1epss 0.01

    Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by…

  • CVE-2019-12752MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.00

    The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.

  • CVE-2018-18370MedAug 30, 2019
    risk 0.40cvss 6.1epss 0.01

    The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in…

  • CVE-2019-9696MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.01

    Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by…

  • CVE-2018-18363MedJan 24, 2019
    risk 0.40cvss 6.2epss 0.00

    Norton App Lock prior to 1.4.0.445 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.

  • CVE-2018-18362MedDec 6, 2018
    risk 0.40cvss 6.1epss 0.01

    Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting…

  • CVE-2018-12241MedNov 27, 2018
    risk 0.40cvss 6.1epss 0.01

    The Symantec Security Analytics (SA) 7.x prior to 7.3.4 Web UI is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker with knowledge of the SA web UI hostname or IP address can craft a malicious URL for the SA web UI and target SA web UI users…

  • CVE-2018-12246MedOct 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack…

  • CVE-2018-5239MedJul 16, 2018
    risk 0.40cvss 6.2epss 0.00

    Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.

  • CVE-2018-5242MedJun 13, 2018
    risk 0.40cvss 6.2epss 0.00

    Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.

  • CVE-2016-10257MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.01

    The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console…

  • CVE-2016-10256MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.01

    The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the…

  • CVE-2017-15529MedDec 13, 2017
    risk 0.40cvss 6.2epss 0.00

    Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular device unavailable to its intended user by temporarily or indefinitely disrupting…

  • CVE-2016-9099MedMay 11, 2017
    risk 0.40cvss 6.1epss 0.02

    Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console URL in a phishing…

  • CVE-2025-32987MedApr 15, 2025
    risk 0.39cvss 6.0epss 0.00

    Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

  • CVE-2018-5235MedAug 22, 2018
    risk 0.39cvss 6.0epss 0.00

    Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is…

  • CVE-2017-15533MedMay 17, 2018
    risk 0.39cvss 5.9epss 0.02

    Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the oracle classification used in the ROBOT…

  • CVE-2016-5310MedApr 14, 2017
    risk 0.39cvss 5.5epss 0.05

    The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint…

  • CVE-2016-5309MedApr 14, 2017
    risk 0.39cvss 5.5epss 0.07

    The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint…

  • CVE-2023-23956MedMay 30, 2023
    risk 0.38cvss 5.4epss 0.03

    A user can supply malicious HTML and JavaScript code that will be executed in the client browser

  • CVE-2022-25630MedDec 9, 2022
    risk 0.38cvss 5.4epss 0.01

    An authenticated user can embed malicious content with XSS into the admin group policy page.

  • CVE-2019-18376MedApr 10, 2020
    risk 0.38cvss 5.9epss 0.01

    A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

  • CVE-2018-12240MedAug 29, 2018
    risk 0.38cvss 5.9epss 0.01

    The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.

  • CVE-2017-18268MedMay 17, 2018
    risk 0.38cvss 5.9epss 0.02

    Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the…

  • CVE-2016-10259MedApr 11, 2017
    risk 0.38cvss 5.9epss 0.01

    Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily…

  • CVE-2016-3652MedJun 30, 2016
    risk 0.38cvss 5.4epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-6551MedMay 7, 2016
    risk 0.38cvss 5.9epss 0.01

    Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS for administration-console traffic to the NBU server, which allows remote attackers to obtain sensitive information by sniffing the…

  • CVE-2017-15532MedDec 20, 2017
    risk 0.37cvss 5.7epss 0.01

    Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to…

  • CVE-2017-13683MedOct 23, 2017
    risk 0.37cvss 5.7epss 0.00

    In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released. In object-oriented…

  • CVE-2017-13682MedOct 23, 2017
    risk 0.37cvss 5.7epss 0.00

    In Symantec Encryption Desktop before SED 10.4.1 MP2HF1, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released. In object-oriented…

  • CVE-2016-2206MedJul 12, 2016
    risk 0.37cvss 5.7epss 0.01

    The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the…

  • CVE-2016-2205MedJul 12, 2016
    risk 0.37cvss 5.7epss 0.02

    Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6…

  • CVE-2020-5826MedFeb 11, 2020
    risk 0.36cvss 5.5epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing…

  • CVE-2020-5825MedFeb 11, 2020
    risk 0.36cvss 5.5epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able…

  • CVE-2020-5824MedFeb 11, 2020
    risk 0.36cvss 5.5epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a denial of service vulnerability, which is a type of issue whereby a threat actor attempts…

  • CVE-2016-6587MedJan 8, 2020
    risk 0.36cvss 5.5epss 0.00

    An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malicious user obtain sensitive information.

  • CVE-2019-18373MedNov 18, 2019
    risk 0.36cvss 5.6epss 0.00

    Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain access.

  • CVE-2019-12755MedSep 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.

  • CVE-2019-9698MedMay 8, 2019
    risk 0.36cvss 5.5epss 0.00

    Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulnerability that could allow an attacker to delete files on the resident system without elevated privileges.

  • CVE-2011-3477MedFeb 19, 2018
    risk 0.36cvss 5.5epss 0.01

    GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.

  • CVE-2017-13680MedNov 6, 2017
    risk 0.36cvss 5.5epss 0.00

    Prior to SEP 12.1 RU6 MP9 & SEP 14 RU1 Symantec Endpoint Protection Windows endpoint can encounter a situation whereby an attacker could use the product's UI to perform unauthorized file deletes on the resident file system.

  • CVE-2017-6404MedMar 2, 2017
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction or spoofing of log data.

  • CVE-2016-5308MedJul 12, 2016
    risk 0.36cvss 5.5epss 0.02

    The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memory corruption and system crash) via a malformed Portable Executable (PE) file.

  • CVE-2016-2202MedApr 20, 2016
    risk 0.36cvss 5.5epss 0.00

    The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restrictions via unspecified vectors.

Page 6 of 16