Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Protection Manager MEDIUM 5.5
CVE-2015-1490

Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote aut…

Mitigation only
Fix from $1,600 2015-08-01
Endpoint Protection Manager HIGH 8.5
CVE-2015-1489EPSS 25%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges v…

No fix yet
Fix from $1,950 2015-08-01
Endpoint Protection Manager MEDIUM 5.5
CVE-2015-1487EPSS 52%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrar…

No fix yet
Fix from $1,600 2015-08-01
Endpoint Protection Manager HIGH 7.5
CVE-2015-1486EPSS 68%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a…

No fix yet
Fix from $1,950 2015-08-01
Data Loss Prevention MEDIUM 6.8
CVE-2015-1485

Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.…

Fix: after 12.5.1
Fix from $1,600 2015-06-28
Workspace Streaming MEDIUM 6.9
CVE-2015-1484

Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when App…

Mitigation only
Fix from $1,600 2015-04-22
Netbackup Opscenter HIGH 7.5
CVE-2015-1483

Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vec…

Mitigation only
Fix from $1,950 2015-03-06
Encryption Management Server HIGH 9.0
CVE-2014-7288EPSS 8%

Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell …

Fix: after 3.3.2
Fix from $1,950 2015-02-01
Encryption Management Server MEDIUM 5.0
CVE-2014-7287

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger un…

Fix: after 3.3.2
Fix from $1,600 2015-02-01
Deployment Solution HIGH 7.2
CVE-2014-7286

Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via un…

Fix: after 6.9
Fix from $1,950 2014-12-22
Web Gateway MEDIUM 6.5
CVE-2014-7285EPSS 50%

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by…

Fix: after 5.2.1
Fix from $1,600 2014-12-17
Endpoint Protection Manager HIGH 7.5
CVE-2014-3437EPSS 9%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP req…

Fix: after 12.1.4
Fix from $1,950 2014-11-07
Endpoint Protection Manager MEDIUM 6.1
CVE-2014-3439EPSS 6%

ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vec…

Fix: after 12.1.4
Fix from $1,600 2014-11-07
Pgp Desktop MEDIUM 5.0
CVE-2014-3436

Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2014-08-22
Endpoint Protection MEDIUM 6.9
CVE-2014-3434

Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition be…

No fix yet
Fix from $1,600 2014-08-06
Web Gateway CRITICAL 9.8
CVE-2013-5017EPSS 7%

SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspeci…

Fix: after 5.2
Fix from $2,300 2014-06-18
Web Gateway MEDIUM 5.8
CVE-2014-1651

SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute…

Fix: after 5.1.1
Fix from $1,600 2014-06-18
Web Gateway MEDIUM 5.2
CVE-2014-1650

SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to exe…

Fix: after 5.2
Fix from $1,600 2014-06-18
Workspace Streaming HIGH 7.9
CVE-2014-1649EPSS 42%

The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLR…

Fix: after 7.5.0
Fix from $1,950 2014-05-16
Liveupdate Administrator HIGH 7.5
CVE-2014-1644

The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote …

Fix: after 2.3.2
Fix from $1,950 2014-03-29
Liveupdate Administrator HIGH 7.5
CVE-2014-1645

SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote att…

Fix: after 2.3.2
Fix from $1,950 2014-03-29
Endpoint Protection Manager MEDIUM 6.5
CVE-2013-5015EPSS 29%

SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.…

No fix yet
Fix from $1,600 2014-02-14
Endpoint Protection Manager HIGH 7.5
CVE-2013-5014EPSS 68%

The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protect…

No fix yet
Fix from $1,950 2014-02-14
Web Gateway MEDIUM 6.5
CVE-2013-5012

Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote authenticated us…

Fix: after 5.1.1
Fix from $1,600 2014-02-11
Endpoint Protection HIGH 7.4
CVE-2013-5009

The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business E…

Fix: after 11.0.7.3
Fix from $1,950 2014-01-10
Endpoint Protection HIGH 7.2
CVE-2013-5011

Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and En…

Fix: after 11.0.7.3
Fix from $1,950 2014-01-10
Backup Exec HIGH 7.9
CVE-2013-4575

Heap-based buffer overflow in the utility program in the Linux agent in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows re…

Mitigation only
Fix from $1,950 2013-08-05
Encryption Desktop MEDIUM 6.8
CVE-2013-1610

Unquoted Windows search path vulnerability in RDDService in Symantec PGP Desktop 10.0.x through 10.2.x and Symantec Encryption Desktop 10.3.0 before …

Mitigation only
Fix from $1,600 2013-08-05
Workspace Virtualization MEDIUM 6.6
CVE-2013-4679

Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows local users to gain privileges…

Fix: after 6.4.1895.0
Fix from $1,600 2013-08-05
Web Gateway HIGH 8.3
CVE-2013-1616EPSS 11%

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a …

Fix: after 5.1
Fix from $1,950 2013-08-01