Skip to main content

Vendor archive

symantec CVEs

Beta · best-effort

568 CVEs tagged to vendor symantec86 Critical, 184 High, 258 Medium, 40 Low, 0 Unrated.

CVE-2011-0549

Published Jul 11, 2011

SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0546

Published May 31, 2011

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1524

Published Mar 28, 2011

Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0545

Published Mar 28, 2011

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of adminis…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3719

Published Feb 2, 2011

Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code v…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0114

Published Dec 22, 2010

fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0113

Published Nov 15, 2010

The Symantec Norton Mobile Security application 1.0 Beta for Android records setup details, possibly including wipe/lock credentials, in the device logs, which allows user-assiste…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0112

Published Oct 28, 2010

Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2305

Published Jun 16, 2010

Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argum…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3036

Published Feb 23, 2010

Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3035

Published Feb 2, 2010

The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1575

Published Jan 28, 2010

VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circu…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 568 CVEsPage 13 of 23