Skip to main content

Vendor/product archive

symantec / messaging_gateway CVEs

Beta · best-effort

25 CVEs tagged to symantec / messaging_gateway2 Critical, 9 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2022-25629

Published Dec 9, 2022

An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation T…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18379

Published Dec 11, 2019

Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted req…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18378

Published Dec 11, 2019

Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18377

Published Dec 11, 2019

Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9699

Published Oct 24, 2019

Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized acc…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12243

Published Sep 19, 2018

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12242

Published Sep 19, 2018

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially cir…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15532

Published Dec 20, 2017

Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and direc…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6326

Published Jun 26, 2017

The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remote…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6325

Published Jun 26, 2017

The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6324

Published Jun 26, 2017

The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the ad…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5312

Published Apr 14, 2017

Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2204

Published Apr 22, 2016

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2203

Published Apr 22, 2016

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1648

Published Apr 23, 2014

Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4347

Published Dec 5, 2012

Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a ..…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3581

Published Aug 29, 2012

Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to obtain potentially sensitive information about component versions via unspecified vectors.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3580

Published Aug 29, 2012

Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2012-3579

Published Aug 29, 2012

Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH s…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0308

Published Aug 29, 2012

Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0307

Published Aug 29, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web conte…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1