Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Protection Engine MEDIUM 6.5
CVE-2023-23958

Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.

Fix: 9.1.0+
Fix from $1,600 2023-09-27
Identity Portal MEDIUM 5.4
CVE-2023-23957

An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4

No fix yet
Fix from $1,600 2023-09-19
Messaging Gateway MEDIUM 5.4
CVE-2022-25629

An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the …

Fix: 10.8+
Fix from $1,600 2022-12-09
Messaging Gateway MEDIUM 5.4
CVE-2022-25630

An authenticated user can embed malicious content with XSS into the admin group policy page.

Fix: 10.8+
Fix from $1,600 2022-12-09
Endpoint Detection And Response CRITICAL 9.8
CVE-2022-37015

Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a typ…

Fix: 4.7.0+
Fix from $2,300 2022-11-08
Management Agent HIGH 7.8
CVE-2022-25623

The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM lev…

Mitigation only
Fix from $1,950 2022-03-04
Security Analytics CRITICAL 9.8
CVE-2021-30642

An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allow…

Fix: 7.2.7 / 8.1.3-nsr3+
Fix from $2,300 2021-04-27
Endpoint Detection And Response HIGH 7.5
CVE-2020-12593

Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that co…

Fix: 4.5+
Fix from $1,950 2020-11-18
Endpoint Detection And Response HIGH 7.5
CVE-2020-5839

Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that …

Fix: 4.4+
Fix from $1,950 2020-07-08
Endpoint Protection HIGH 7.8
CVE-2020-5836

Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper P…

Fix: 14.3+
Fix from $1,950 2020-05-11
Endpoint Protection HIGH 7.8
CVE-2020-5837

Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which ca…

Fix: 14.3+
Fix from $1,950 2020-05-11
Endpoint Protection Manager HIGH 7.0
CVE-2020-5835

Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege o…

Fix: 14.3+
Fix from $1,950 2020-05-11
Endpoint Protection Manager MEDIUM 5.3
CVE-2020-5834

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine …

Fix: 14.3+
Fix from $1,600 2020-05-11
Management Center MEDIUM 5.9
CVE-2019-18376

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or …

Mitigation only
Fix from $1,600 2020-04-10
Data Center Security HIGH 7.8
CVE-2020-5832

Symantec Data Center Security Manager Component, prior to 6.8.2 (aka 6.8 MP2), may be susceptible to a privilege escalation vulnerability, which is a…

Fix: 6.8.2+
Fix from $1,950 2020-04-06
Data Loss Prevention Enforce\/detection Servers HIGH 7.8
CVE-2012-6277EPSS 8%

Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Sy…

Fix: 10.0.1 / 10.16+
Fix from $1,950 2020-02-21
Endpoint Protection MEDIUM 5.5
CVE-2020-5826

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,600 2020-02-11
Endpoint Protection HIGH 7.8
CVE-2020-5820

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,950 2020-02-11
Endpoint Protection HIGH 7.8
CVE-2020-5821

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,950 2020-02-11
Endpoint Protection HIGH 7.8
CVE-2020-5822

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,950 2020-02-11
Endpoint Protection HIGH 7.8
CVE-2020-5823

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,950 2020-02-11
Endpoint Protection MEDIUM 5.5
CVE-2020-5824

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,600 2020-02-11
Endpoint Protection MEDIUM 5.5
CVE-2020-5825

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,600 2020-02-11
Norton Download Manager HIGH 7.8
CVE-2016-6592

A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when…

Fix: 5.6+
Fix from $1,950 2020-01-14
Endpoint Protection HIGH 7.8
CVE-2016-5311

A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup,…

Fix: 22.7 / 22.8.0.50+
Fix from $1,950 2020-01-09
Norton Mobile Security MEDIUM 5.3
CVE-2016-6585

A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduc…

Fix: 3.16+
Fix from $1,600 2020-01-08
Norton Mobile Security MEDIUM 5.5
CVE-2016-6587

An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, …

Fix: 3.16+
Fix from $1,600 2020-01-08
It Management Suite MEDIUM 5.4
CVE-2016-6588

A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.

Mitigation only
Fix from $1,600 2020-01-08
Encryption Desktop HIGH 7.8
CVE-2016-6590

A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suit…

Fix: 7.6 / 10.4.1+
Fix from $1,950 2020-01-08
Vip Access Desktop HIGH 7.8
CVE-2016-6593

A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local mal…

Fix: 2.2.2+
Fix from $1,950 2020-01-08