Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Gateway HIGH 7.4
CVE-2013-1617EPSS 7%

Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote authenticated …

Fix: after 5.1
Fix from $1,950 2013-08-01
Web Gateway HIGH 7.2
CVE-2013-4672

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass int…

Fix: after 5.1
Fix from $1,950 2013-08-01
Web Gateway MEDIUM 6.0
CVE-2013-4671

Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote auth…

Fix: after 5.1
Fix from $1,600 2013-08-01
Web Gateway MEDIUM 5.8
CVE-2013-4673

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remot…

Fix: after 5.1
Fix from $1,600 2013-08-01
Endpoint Protection Manager HIGH 7.9
CVE-2013-1612

Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Pr…

Mitigation only
Fix from $1,950 2013-06-20
Enterprise Vault For File System Archiving HIGH 7.8
CVE-2013-1609

Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) f…

Fix: after 9.0.3
Fix from $1,950 2013-03-26
Netbackup Appliance MEDIUM 6.7
CVE-2013-1608

Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary…

Mitigation only
Fix from $1,600 2013-03-26
Encryption Desktop MEDIUM 6.9
CVE-2012-4351

Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a cra…

Mitigation only
Fix from $1,600 2013-02-18
Endpoint Protection HIGH 7.2
CVE-2012-4348

The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business…

Mitigation only
Fix from $1,950 2012-12-18
Enterprise Security Manager HIGH 7.2
CVE-2012-4350

Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise Security Manager (ESM) befor…

Fix: after 10.0
Fix from $1,950 2012-12-18
Network Access Control HIGH 7.2
CVE-2012-4349

Unquoted Windows search path vulnerability in Symantec Network Access Control (SNAC) 12.1 before RU2 allows local users to gain privileges via unspec…

Mitigation only
Fix from $1,950 2012-12-11
Messaging Gateway MEDIUM 5.0
CVE-2012-4347EPSS 59%

Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to …

No fix yet
Fix from $1,600 2012-12-05
Antivirus HIGH 9.3
CVE-2012-4953EPSS 6%

The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corpor…

Fix: after 5.2
Fix from $1,950 2012-11-14
Ghost Solutions Suite MEDIUM 6.8
CVE-2012-0306

Symantec Ghost Solution Suite 2.x through 2.5.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vi…

Mitigation only
Fix from $1,600 2012-10-18
Messaging Gateway HIGH 7.9
CVE-2012-3579EPSS 40%

Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain …

Fix: after 9.5.4
Fix from $1,950 2012-08-29
Messaging Gateway HIGH 7.7
CVE-2012-3580

Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management i…

Fix: after 9.5.4
Fix from $1,950 2012-08-29
Messaging Gateway MEDIUM 6.8
CVE-2012-0308

Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication …

Fix: after 9.5.4
Fix from $1,600 2012-08-29
Norton Internet Security 2010 MEDIUM 6.2
CVE-2010-5168

Race condition in Symantec Norton Internet Security 2010 17.5.0.127 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute…

Mitigation only
Fix from $1,600 2012-08-25
Norton Antivirus MEDIUM 6.4
CVE-2010-3497

Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it…

Mitigation only
Fix from $1,600 2012-08-22
Web Gateway HIGH 7.5
CVE-2012-4178

SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQ…

No fix yet
Fix from $1,950 2012-08-07
Web Gateway HIGH 10.0
CVE-2012-2953EPSS 67%

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to appli…

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway HIGH 10.0
CVE-2012-2976EPSS 5%

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to…

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway HIGH 7.5
CVE-2012-2574

SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL …

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway HIGH 7.5
CVE-2012-2961

SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL …

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway HIGH 7.2
CVE-2012-2957EPSS 59%

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inc…

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway MEDIUM 5.0
CVE-2012-2977

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an ap…

Mitigation only
Fix from $1,600 2012-07-23
Message Filter MEDIUM 6.8
CVE-2012-0303

Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hija…

Fix: after 6.3
Fix from $1,600 2012-07-05
Message Filter MEDIUM 5.4
CVE-2012-0301

Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspeci…

Fix: after 6.3
Fix from $1,600 2012-07-05
Liveupdate Administrator MEDIUM 6.9
CVE-2012-0304

Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local user…

Fix: after 2.3.0
Fix from $1,600 2012-06-22
Endpoint Protection MEDIUM 5.0
CVE-2012-1821

The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 200…

Mitigation only
Fix from $1,600 2012-05-24