Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Protection HIGH 7.1
CVE-2017-6331

Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses …

Fix: 14.0+
Fix from $1,950 2017-11-06
Endpoint Protection MEDIUM 5.5
CVE-2017-13680

Prior to SEP 12.1 RU6 MP9 & SEP 14 RU1 Symantec Endpoint Protection Windows endpoint can encounter a situation whereby an attacker could use the prod…

Fix: 12.1+
Fix from $1,600 2017-11-06
Encryption Desktop MEDIUM 5.7
CVE-2017-13682

In Symantec Encryption Desktop before SED 10.4.1 MP2HF1, a kernel memory leak is a type of resource leak that can occur when a computer program incor…

Fix: after 10.4.1
Fix from $1,600 2017-10-23
Endpoint Encryption MEDIUM 5.7
CVE-2017-13683

In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur when a computer program incorrec…

Mitigation only
Fix from $1,600 2017-10-23
Encryption Desktop MEDIUM 6.5
CVE-2017-6330

Symantec Encryption Desktop before SED 10.4.1MP2 can allow remote attackers to cause a denial of service (resource consumption) via crafted web reque…

Fix: after 10.4.1
Fix from $1,600 2017-09-13
Malware Analysis Appliance CRITICAL 9.3
CVE-2015-4523

Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechani…

Fix: after 4.2
Fix from $2,300 2017-09-11
Proxyclient HIGH 7.8
CVE-2017-13674

Symantec ProxyClient 3.4 for Windows is susceptible to a privilege escalation vulnerability. A malicious local Windows user can, under certain circum…

Mitigation only
Fix from $1,950 2017-09-01
Vip Access For Desktop HIGH 7.8
CVE-2017-6329

Symantec VIP Access for Desktop prior to 2.2.4 can be susceptible to a DLL Pre-Loading vulnerability. These types of issues occur when an application…

Fix: after 2.2.3
Fix from $1,950 2017-08-21
Message Gateway HIGH 8.8
CVE-2017-6327 KEVEPSS 35%

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual m…

Fix: 10.6.3-267+
Fix from $1,950 2017-08-11
Message Gateway HIGH 8.8
CVE-2017-6328

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbrevia…

Fix: after 10.6.3-2
Fix from $1,950 2017-08-11
Messaging Gateway CRITICAL 10.0
CVE-2017-6326EPSS 73%

The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the abil…

Fix: after 10.6.3
Fix from $2,300 2017-06-26
Messaging Gateway HIGH 7.3
CVE-2017-6324

The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially maliciou…

Fix: after 10.6.2
Fix from $1,950 2017-06-26
Messaging Gateway MEDIUM 6.6
CVE-2017-6325

The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect w…

Fix: after 10.6.2
Fix from $1,600 2017-06-26
Content Analysis HIGH 8.8
CVE-2016-9092

The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site r…

Mitigation only
Fix from $1,950 2017-05-11
Messaging Gateway MEDIUM 6.5
CVE-2016-5312EPSS 54%

Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arb…

Fix: after 10.6.1
Fix from $1,600 2017-04-14
Web Gateway HIGH 8.8
CVE-2016-5313

Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

Fix: after 5.2.2
Fix from $1,950 2017-04-12
Client Intrusion Detection System MEDIUM 5.5
CVE-2016-5308

The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows r…

Fix: 15.0.6 / 15.1.2+
Fix from $1,600 2016-07-12
Workspace Streaming MEDIUM 5.7
CVE-2016-2206

The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization …

Mitigation only
Fix from $1,600 2016-07-12
Workspace Streaming MEDIUM 5.7
CVE-2016-2205

Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x befor…

Mitigation only
Fix from $1,600 2016-07-12
Endpoint Protection Manager MEDIUM 5.3
CVE-2016-5306

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for …

Fix: after 12.1.6
Fix from $1,600 2016-06-30
Endpoint Protection Manager MEDIUM 5.4
CVE-2016-5305

Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow re…

Fix: after 12.1.6
Fix from $1,600 2016-06-30
Endpoint Protection Manager MEDIUM 6.8
CVE-2016-5304

Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authentica…

Fix: after 12.1.6
Fix from $1,600 2016-06-30
Endpoint Protection Manager HIGH 8.0
CVE-2016-3653

Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 a…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Endpoint Protection Manager MEDIUM 5.4
CVE-2016-3652

Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow re…

Fix: after 12.1.6
Fix from $1,600 2016-06-30
Endpoint Protection Manager HIGH 8.0
CVE-2016-3651

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover the PHP JSESSIONID value via unspecifie…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Endpoint Protection Manager HIGH 8.8
CVE-2016-3650

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Endpoint Protection Manager HIGH 8.8
CVE-2016-3648

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechan…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Endpoint Protection Manager HIGH 7.7
CVE-2016-3647

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attac…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Norton Security HIGH 8.4
CVE-2016-3646EPSS 18%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 2016.0
Fix from $1,950 2016-06-30
Norton Security CRITICAL 9.8
CVE-2016-3645EPSS 25%

Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…

Fix: after 2016.0
Fix from $2,300 2016-06-30