Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mail Security HIGH 7.8
CVE-2007-1792

libdayzero.dll in the Filter Hub Service (filter-hub.exe) in Symantec Mail Security for SMTP before 5.0.1 Patch 181 and Mail Security Appliance befor…

Patch available
Fix from $1,950 2007-06-27
Ghost Solutions Suite MEDIUM 5.0
CVE-2007-3132

Multiple vulnerabilities in Symantec Ghost Solution Suite 2.0.0 and earlier, with Ghost 8.0.992 and possibly other versions, allow remote attackers t…

Fix: after 2.0
Fix from $1,600 2007-06-08
Client Security HIGH 9.0
CVE-2007-3095

Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and la…

Fix: after 1.0.197.0
Fix from $1,950 2007-06-06
Client Security HIGH 7.5
CVE-2007-3021

Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus C…

Fix: after 1.0.197.0
Fix from $1,950 2007-06-05
Veritas Storage Foundation HIGH 9.3
CVE-2007-2279EPSS 6%

The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execut…

Patch available
Fix from $1,950 2007-06-04
Veritas Volume Replicator MEDIUM 5.0
CVE-2007-1593

The administrative service in Symantec Veritas Volume Replicator (VVR) for Windows 3.1 through 4.3, and VVR for Unix 3.5 through 5.0, in Symantec Sto…

Patch available
Fix from $1,600 2007-06-04
Norton Internet Security HIGH 10.0
CVE-2007-1689EPSS 64%

Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote atta…

Patch available
Fix from $1,950 2007-05-16
Norton Antivirus HIGH 8.5
CVE-2006-3456

The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and Sy…

Mitigation only
Fix from $1,950 2007-05-11
Enterprise Security Manager HIGH 10.0
CVE-2007-2375EPSS 5%

The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which …

Patch available
Fix from $1,950 2007-04-30
Backupexec System Recovery HIGH 7.2
CVE-2007-2359

Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recover…

Mitigation only
Fix from $1,950 2007-04-30
Backupexec System Recovery MEDIUM 6.8
CVE-2007-2360

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore poi…

Mitigation only
Fix from $1,600 2007-04-30
Mail Security HIGH 9.3
CVE-2007-1252EPSS 7%

Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly exe…

Patch available
Fix from $1,950 2007-03-03
Veritas Netbackup Client HIGH 10.0
CVE-2006-4902

The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly c…

Patch available
Fix from $1,950 2006-12-14
Veritas Netbackup Client HIGH 10.0
CVE-2006-5822EPSS 12%

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 bef…

Patch available
Fix from $1,950 2006-12-14
Veritas Netbackup Client HIGH 10.0
CVE-2006-6222EPSS 12%

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 bef…

Patch available
Fix from $1,950 2006-12-14
Mail Security MEDIUM 5.0
CVE-2006-5545

Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote …

Patch available
Fix from $1,600 2006-10-26
Automated Support Assistant MEDIUM 5.1
CVE-2006-5403EPSS 6%

Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and S…

Mitigation only
Fix from $1,600 2006-10-19
Client Security HIGH 7.2
CVE-2006-3454

Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users t…

Patch available
Fix from $1,950 2006-09-14
Gateway Security MEDIUM 5.0
CVE-2006-4562

The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hidi…

Mitigation only
Fix from $1,600 2006-09-06
Enterprise Security Manager MEDIUM 5.0
CVE-2006-4314

The manager server in Symantec Enterprise Security Manager (ESM) 6 and 6.5.x allows remote attackers to cause a denial of service (hang) via a malfor…

Patch available
Fix from $1,600 2006-08-23
Brightmail Antispam HIGH 7.6
CVE-2006-4013

Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from …

Patch available
Fix from $1,950 2006-08-07
Brightmail Antispam MEDIUM 5.0
CVE-2006-4014

Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a…

Patch available
Fix from $1,600 2006-08-07
Pcanywhere HIGH 7.2
CVE-2006-3784

Symantec pcAnywhere 12.5 uses weak default permissions for the "Symantec\pcAnywhere\Hosts" folder, which allows local users to gain privileges by ins…

Mitigation only
Fix from $1,950 2006-07-24
Client Security HIGH 10.0
CVE-2006-2630EPSS 74%

Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack v…

Patch available
Fix from $1,950 2006-05-27
Enterprise Firewall MEDIUM 5.0
CVE-2006-2341

The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers t…

Patch available
Fix from $1,600 2006-05-12
Antivirus Scan Engine HIGH 10.0
CVE-2006-0230EPSS 16%

Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attacke…

Patch available
Fix from $1,950 2006-04-25
Antivirus Scan Engine MEDIUM 6.4
CVE-2006-0231

Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote a…

Patch available
Fix from $1,600 2006-04-25
Antivirus Scan Engine MEDIUM 5.0
CVE-2006-0232

Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with in…

Patch available
Fix from $1,600 2006-04-25
Liveupdate MEDIUM 6.8
CVE-2006-1836

Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path,…

Patch available
Fix from $1,600 2006-04-19
Sygate Management Server HIGH 7.5
CVE-2006-0522

SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote…

Fix: after 4.1_mr_2_build_1417_english
Fix from $1,950 2006-02-02