Vulnerability index

Browse CVEs

409 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Protection HIGH 9.3
CVE-2012-0295

The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…

Mitigation only
Fix from $1,950 2012-05-23
Endpoint Protection HIGH 7.2
CVE-2012-0289

Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.7…

No fix yet
Fix from $1,950 2012-05-23
Endpoint Protection MEDIUM 5.8
CVE-2012-0294

Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 all…

Mitigation only
Fix from $1,600 2012-05-23
Web Gateway HIGH 10.0
CVE-2012-0297EPSS 73%

The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers…

Mitigation only
Fix from $1,950 2012-05-21
Web Gateway HIGH 10.0
CVE-2012-0299EPSS 64%

The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a des…

Mitigation only
Fix from $1,950 2012-05-21
Web Gateway MEDIUM 6.4
CVE-2012-0298EPSS 9%

The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitra…

Mitigation only
Fix from $1,600 2012-05-21
Altiris Wise Package Studio MEDIUM 6.8
CVE-2012-0293

Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands…

Fix: after 8.0
Fix from $1,600 2012-03-17
Pcanywhere MEDIUM 5.0
CVE-2012-0292EPSS 7%

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Al…

Fix: after 12.5
Fix from $1,600 2012-03-08
Pcanywhere MEDIUM 5.0
CVE-2012-0291

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management …

Fix: after 12.5
Fix from $1,600 2012-02-22
Pcanywhere HIGH 10.0
CVE-2012-0290

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management …

Fix: after 12.5.3
Fix from $1,950 2012-02-06
Pcanywhere HIGH 10.0
CVE-2011-3478EPSS 39%

The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 1…

Mitigation only
Fix from $1,950 2012-01-25
Pcanywhere MEDIUM 6.8
CVE-2011-3479

Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable per…

Mitigation only
Fix from $1,600 2012-01-25
Im Manager HIGH 7.5
CVE-2011-0553

SQL injection vulnerability in the management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary SQL commands …

Fix: after 8.4.17
Fix from $1,950 2011-10-02
Im Manager HIGH 7.5
CVE-2011-0554

The management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "…

Fix: after 8.4.17
Fix from $1,950 2011-10-02
Veritas Dynamic Multi Pathing HIGH 10.0
CVE-2011-0547EPSS 7%

Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Verit…

Fix: after 5.1
Fix from $1,950 2011-08-19
Endpoint Protection MEDIUM 6.8
CVE-2011-0551

Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.60…

Mitigation only
Fix from $1,600 2011-08-15
Mail Security HIGH 9.3
CVE-2011-0548EPSS 5%

Buffer overflow in the Lotus Freelance Graphics PRZ file viewer in Autonomy KeyView, as used in Symantec Mail Security (SMS) 6.x through 8.x, Symante…

Fix: after 10.5.2
Fix from $1,950 2011-07-18
Web Gateway HIGH 7.5
CVE-2011-0549

SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL comman…

Mitigation only
Fix from $1,950 2011-07-11
Backup Exec MEDIUM 6.5
CVE-2011-0546

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, w…

Mitigation only
Fix from $1,600 2011-05-31
Liveupdate Administrator MEDIUM 6.8
CVE-2011-0545

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack…

No fix yet
Fix from $1,600 2011-03-28
Altiris Deployment Solution MEDIUM 6.8
CVE-2009-3028EPSS 43%

The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6…

Patch available
Fix from $1,600 2011-03-07
Im Manager HIGH 8.5
CVE-2010-3719EPSS 13%

Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attacke…

Fix: after 8.4.16
Fix from $1,950 2011-02-02
Antivirus HIGH 9.3
CVE-2011-0688

Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente…

Mitigation only
Fix from $1,950 2011-01-31
Antivirus HIGH 9.3
CVE-2010-0111EPSS 35%

HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in S…

Mitigation only
Fix from $1,950 2011-01-31
Antivirus HIGH 7.9
CVE-2010-0110EPSS 5%

Multiple stack-based buffer overflows in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.…

Mitigation only
Fix from $1,950 2011-01-31
Web Gateway HIGH 7.5
CVE-2010-0115

SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execut…

Mitigation only
Fix from $1,950 2011-01-14
Endpoint Protection HIGH 7.5
CVE-2010-0114EPSS 5%

fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote …

Mitigation only
Fix from $1,950 2010-12-22
Im Manager HIGH 7.5
CVE-2010-0112EPSS 6%

Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attacke…

Fix: after 8.4.15
Fix from $1,950 2010-10-28
Workspace Streaming HIGH 9.3
CVE-2008-4389

Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Work…

Mitigation only
Fix from $1,950 2010-06-17
Sygate Personal Firewall HIGH 9.3
CVE-2010-2305EPSS 20%

Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2010-06-16