Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Norton Security HIGH 8.4
CVE-2016-3644EPSS 18%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 2016.0
Fix from $1,950 2016-06-30
Mail Security For Microsoft Exchange HIGH 7.8
CVE-2016-2211EPSS 53%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 10.6.1-3
Fix from $1,950 2016-06-30
Mail Security For Microsoft Exchange HIGH 7.3
CVE-2016-2210EPSS 11%

Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server …

Fix: after 10.6.1-3
Fix from $1,950 2016-06-30
Mail Security For Microsoft Exchange HIGH 7.3
CVE-2016-2209EPSS 21%

Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (…

Fix: after 10.6.1-3
Fix from $1,950 2016-06-30
Mail Security For Microsoft Exchange HIGH 8.4
CVE-2016-2207EPSS 18%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 10.6.1-3
Fix from $1,950 2016-06-30
Anti Virus Engine CRITICAL 9.1
CVE-2016-2208EPSS 19%

The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a deni…

Fix: after 20151.1.0.32
Fix from $2,300 2016-05-19
Endpoint Encryption HIGH 7.8
CVE-2015-8156

Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileg…

Mitigation only
Fix from $1,950 2016-05-14
Messaging Gateway HIGH 8.2
CVE-2016-2204

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted…

Fix: after 10.6.0
Fix from $1,950 2016-04-22
Messaging Gateway HIGH 7.8
CVE-2016-2203EPSS 7%

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by…

No fix yet
Fix from $1,950 2016-04-22
Altiris It Management Suite MEDIUM 5.5
CVE-2016-2202

The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local us…

Fix: after 7.6
Fix from $1,600 2016-04-20
Endpoint Protection Manager HIGH 8.8
CVE-2015-8154EPSS 5%

The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4…

Fix: after 12.1
Fix from $1,950 2016-03-18
Endpoint Protection Manager HIGH 8.8
CVE-2015-8153

SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary…

Fix: after 12.1
Fix from $1,950 2016-03-18
Endpoint Protection Manager HIGH 8.0
CVE-2015-8152

Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users …

Fix: after 12.1
Fix from $1,950 2016-03-18
Encryption Management Server CRITICAL 9.1
CVE-2015-8151

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging conso…

Fix: after 3.3.2
Fix from $2,300 2016-02-18
Encryption Management Server HIGH 7.8
CVE-2015-8150

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

Fix: after 3.3.2
Fix from $1,950 2016-02-18
Encryption Management Server HIGH 7.5
CVE-2015-8148

The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about admi…

Fix: after 3.3.2
Fix from $1,950 2016-02-18
Encryption Management Server HIGH 7.5
CVE-2015-8149

The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory …

Fix: after 3.3.2
Fix from $1,950 2016-02-18
Proxysg Firmware MEDIUM 5.0
CVE-2015-4334

The default configuration of SGOS in Blue Coat ProxySG before 6.2.16.5, 6.5 before 6.5.7.1, and 6.6 before 6.6.2.1 forwards authentication challenges…

Fix: after 6.6.2.0
Fix from $1,600 2015-12-07
Endpoint Protection HIGH 7.2
CVE-2015-8113

Untrusted search path vulnerability in the client in Symantec Endpoint Protection (SEP) 12.1 before 12.1-RU6-MP3 allows local users to gain privilege…

Fix: after 12.1
Fix from $1,950 2015-11-12
Endpoint Protection Manager HIGH 8.5
CVE-2015-6555

Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the cons…

Fix: after 12.1
Fix from $1,950 2015-11-12
Endpoint Protection Manager HIGH 7.5
CVE-2015-6554

Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data.

Fix: after 12.1
Fix from $1,950 2015-11-12
Web Gateway MEDIUM 5.8
CVE-2015-6548

Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 …

Fix: after 5.2.2
Fix from $1,600 2015-09-20
Web Gateway HIGH 8.3
CVE-2015-6547

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute…

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Web Gateway HIGH 7.9
CVE-2015-5693

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute…

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Web Gateway HIGH 7.9
CVE-2015-5692EPSS 5%

admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenti…

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Web Gateway HIGH 8.5
CVE-2015-5690

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass …

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Deployment Solution MEDIUM 6.8
CVE-2015-5689

ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) befor…

Mitigation only
Fix from $1,600 2015-09-20
Endpoint Protection MEDIUM 6.5
CVE-2014-9229

Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow re…

Fix: after 12.1.5
Fix from $1,600 2015-09-20
Endpoint Protection Manager HIGH 8.5
CVE-2015-1492

Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via …

Mitigation only
Fix from $1,950 2015-08-01
Endpoint Protection Manager MEDIUM 6.0
CVE-2015-1491

SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authentic…

Mitigation only
Fix from $1,600 2015-08-01