Filtered by vendor Symantec
Subscribe
Total
569 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-3431 | 2 Apple, Symantec | 3 Mac Os X, Encryption Desktop, Pgp Desktop | 2017-01-06 | 4.3 MEDIUM | N/A |
Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors. | |||||
CVE-2015-1484 | 1 Symantec | 1 Workspace Streaming | 2017-01-02 | 6.9 MEDIUM | N/A |
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe. | |||||
CVE-2014-7285 | 1 Symantec | 1 Web Gateway | 2017-01-02 | 6.5 MEDIUM | N/A |
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts. | |||||
CVE-2015-5691 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php. | |||||
CVE-2015-5689 | 1 Symantec | 2 Deployment Solution, Ghost Solutions Suite | 2016-12-21 | 6.8 MEDIUM | N/A |
ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image. | |||||
CVE-2015-5690 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 8.5 HIGH | N/A |
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect." | |||||
CVE-2015-5692 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 7.9 HIGH | N/A |
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file. | |||||
CVE-2015-5693 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 7.9 HIGH | N/A |
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to "traffic capture." | |||||
CVE-2015-6547 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 8.3 HIGH | N/A |
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors. | |||||
CVE-2015-6548 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 5.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-6549 | 1 Symantec | 1 Netbackup Opscenter | 2016-12-09 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in an application console in the server in Symantec NetBackup OpsCenter before 7.7.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-6555 | 1 Symantec | 1 Endpoint Protection Manager | 2016-12-07 | 8.5 HIGH | N/A |
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the console Java port. | |||||
CVE-2015-6554 | 1 Symantec | 1 Endpoint Protection Manager | 2016-12-07 | 7.5 HIGH | N/A |
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data. | |||||
CVE-2015-8151 | 1 Symantec | 1 Encryption Management Server | 2016-12-05 | 5.8 MEDIUM | 9.1 CRITICAL |
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access. | |||||
CVE-2015-8148 | 1 Symantec | 1 Encryption Management Server | 2016-12-05 | 5.0 MEDIUM | 7.5 HIGH |
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request. | |||||
CVE-2015-8149 | 1 Symantec | 1 Encryption Management Server | 2016-12-05 | 5.0 MEDIUM | 7.5 HIGH |
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests. | |||||
CVE-2015-8150 | 1 Symantec | 1 Encryption Management Server | 2016-12-05 | 6.3 MEDIUM | 7.8 HIGH |
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file. | |||||
CVE-2016-2204 | 1 Symantec | 1 Messaging Gateway | 2016-12-02 | 6.5 MEDIUM | 8.2 HIGH |
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input. | |||||
CVE-2015-8154 | 1 Symantec | 1 Endpoint Protection Manager | 2016-12-02 | 9.3 HIGH | 8.8 HIGH |
The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions." | |||||
CVE-2015-8152 | 1 Symantec | 1 Endpoint Protection Manager | 2016-12-02 | 8.5 HIGH | 8.0 HIGH |
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script. |