VYPR

Vendor CVEs

Symantec

All CVEs

799 total · sorted by risk
  • CVE-2026-44924MedMay 20, 2026
    risk 0.35cvss 5.4epss 0.00

    InfoScale VIOM 9.1.3 allows XSS.

  • CVE-2024-52944MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an…

  • CVE-2024-52943MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an…

  • CVE-2024-52942MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an…

  • CVE-2024-52941MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an…

  • CVE-2023-23957MedSep 19, 2023
    risk 0.35cvss 5.4epss 0.00

    An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4

  • CVE-2022-25629MedDec 9, 2022
    risk 0.35cvss 5.4epss 0.00

    An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).

  • CVE-2022-42301MedOct 3, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.

  • CVE-2022-36948MedJul 27, 2022
    risk 0.35cvss 5.4epss 0.00

    In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2021-41570MedApr 19, 2022
    risk 0.35cvss 5.4epss 0.00

    Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User Name, or NetBackup Password field during a Settings/Configuration Add operation.

  • CVE-2020-36159MedJan 5, 2021
    risk 0.35cvss 5.3epss 0.01

    Veritas Desktop and Laptop Option (DLO) before 9.5 disclosed operational information on the backup processing status through a URL that did not require authentication.

  • CVE-2020-5834MedMay 11, 2020
    risk 0.35cvss 5.3epss 0.02

    Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.

  • CVE-2016-6585MedJan 8, 2020
    risk 0.35cvss 5.3epss 0.01

    A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript.

  • CVE-2016-6588MedJan 8, 2020
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.

  • CVE-2018-5236MedJun 20, 2018
    risk 0.35cvss 5.3epss 0.01

    Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events.

  • CVE-2016-5306MedJun 30, 2016
    risk 0.35cvss 5.3epss 0.02

    Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.

  • CVE-2016-5305MedJun 30, 2016
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via a "DOM link manipulation" attack.

  • CVE-2023-28818MedMar 24, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable…

  • CVE-2022-42307MedOct 3, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.

  • CVE-2022-42305MedOct 3, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.

  • CVE-2022-42299MedOct 3, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a denial of service attack through the DiscoveryService service.

  • CVE-2022-26778MedMar 10, 2022
    risk 0.34cvss 5.3epss 0.00

    Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network file system that they were not authorized…

  • CVE-2019-9701MedJun 19, 2019
    risk 0.34cvss 4.8epss 0.02

    DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to…

  • CVE-2022-26484MedMar 4, 2022
    risk 0.32cvss 4.9epss 0.03

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on…

  • CVE-2019-12753MedAug 30, 2019
    risk 0.32cvss 4.9epss 0.01

    An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authenticated administrator user to obtain passwords for external SMTP, FTP, FTPS, LDAP, and Cloud Log Download servers that they might not otherwise be authorized to…

  • CVE-2025-43704MedApr 16, 2025
    risk 0.31cvss 4.7epss 0.00

    Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.

  • CVE-2022-26483MedMar 4, 2022
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web…

  • CVE-2020-5838MedMay 13, 2020
    risk 0.31cvss 4.8epss 0.01

    Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.

  • CVE-2019-18378MedDec 11, 2019
    risk 0.31cvss 4.8epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by…

  • CVE-2019-12754MedAug 30, 2019
    risk 0.31cvss 4.8epss 0.01

    Symantec My VIP portal, previous version which has already been auto updated, was susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users or potentially bypass…

  • CVE-2019-14415MedJul 29, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a…

  • CVE-2017-13678MedApr 11, 2018
    risk 0.31cvss 4.8epss 0.01

    Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.

  • CVE-2025-13919MedJan 28, 2026
    risk 0.29cvss 4.4epss 0.00

    Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the…

  • CVE-2019-9699MedOct 24, 2019
    risk 0.29cvss 4.5epss 0.00

    Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2017-15525MedNov 13, 2017
    risk 0.29cvss 4.5epss 0.00

    Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a denial of service (DoS) attack, which is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or…

  • CVE-2022-42300MedOct 3, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server nbars process can be crashed resulting in a denial of service. (Note: the watchdog service will automatically restart the process.)

  • CVE-2022-36996MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with access to a NetBackup Client could remotely gather information about any host known to…

  • CVE-2022-36995MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily create directories on a…

  • CVE-2022-36953MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2016-5307MedJun 30, 2016
    risk 0.28cvss 4.3epss 0.03

    Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.

  • CVE-2016-3649MedJun 30, 2016
    risk 0.28cvss 4.3epss 0.02

    Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.

  • CVE-2017-13679MedOct 10, 2017
    risk 0.27cvss 4.2epss 0.00

    A denial of service (DoS) attack in Symantec Encryption Desktop before SED 10.4.1 MP2HF1 allows remote attackers to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a…

  • CVE-2017-13675MedOct 10, 2017
    risk 0.27cvss 4.2epss 0.00

    A denial of service (DoS) attack in Symantec Endpoint Encryption before SEE 11.1.3HF2 allows remote attackers to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.

  • CVE-2016-6586LowJan 8, 2020
    risk 0.24cvss 3.7epss 0.01

    A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.

  • CVE-2020-5833LowMay 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

  • CVE-2020-5831LowFeb 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

  • CVE-2020-5830LowFeb 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

  • CVE-2020-5829LowFeb 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

  • CVE-2020-5828LowFeb 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

  • CVE-2020-5827LowFeb 11, 2020
    risk 0.21cvss 3.3epss 0.00

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

Page 7 of 16