Skip to main content

Vendor archive

symantec CVEs

Beta · best-effort

568 CVEs tagged to vendor symantec86 Critical, 184 High, 258 Medium, 40 Low, 0 Unrated.

CVE-2005-3270

Published Oct 21, 2005

Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1)…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2759

Published Oct 20, 2005

** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privile…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3217

Published Oct 14, 2005

Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2766

Published Sep 2, 2005

Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2017

Published Aug 30, 2005

Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduct…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-1970

Published Jun 16, 2005

Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1867

Published Jun 9, 2005

Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0249

Published Feb 8, 2005

Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative v…

CVSS 7.5 · High

CVE-2004-1483

Published Dec 31, 2004

Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1910

Published Dec 31, 2004

rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2147

Published Dec 31, 2004

Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) wi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2609

Published Dec 31, 2004

The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain acco…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2755

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the quer…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1768

Published Dec 17, 2004

The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 568 CVEsPage 20 of 23