Symantec kayıtları
symantec üreticisine ait 571 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,2
- Silahlaştırılmış
- 27 · %4,7
- Pre-auth RCE
- 96
- Düzeltme kaydı olan
- %0,9
- Yayından KEV’e ortanca
- 1545 gün
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls47
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer42
- CWE-20 Improper Input Validation30
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor22
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')21
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
571 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
76Bu hafta | CVE-2017-6327Silahlaştırılmış | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an indsymantec · message gateway · CWE-77 | Yüksek8,8 | KEV | %35,9 | 11 Ağu 2017 |
66Bu hafta | CVE-2009-1429Silahlaştırılmış | The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec Ansymantec · antivirus · CWE-94 | Kritik10,0 | — | %87,7 | 29 Nis 2009 |
62Bu hafta | CVE-2006-2630Silahlaştırılmış | Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknownsymantec · client security | Kritik10,0 | — | %73,6 | 27 May 2006 |
62Bu hafta | CVE-2012-0297Silahlaştırılmış | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote symantec · web gateway · CWE-264 | Kritik10,0 | — | %73,0 | 21 May 2012 |
62Bu hafta | CVE-2017-6326Silahlaştırılmış | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtainsymantec · messaging gateway | Kritik10,0 | — | %72,8 | 26 Haz 2017 |
60Bu hafta | CVE-2012-2953Silahlaştırılmış | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted inputsymantec · web gateway · CWE-78 | Kritik10,0 | — | %67,4 | 23 Tem 2012 |
60Bu hafta | CVE-2007-1689Silahlaştırılmış | Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows resymantec · norton internet security | Kritik10,0 | — | %65,0 | 16 May 2007 |
59Planlayın | CVE-2012-0299Silahlaştırılmış | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codesymantec · web gateway · CWE-264 | Kritik10,0 | — | %63,7 | 21 May 2012 |
54Planlayın | CVE-2009-1430Silahlaştırılmış | Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as usedsymantec · antivirus · CWE-119 | Kritik9,3 | — | %55,1 | 29 Nis 2009 |
52Planlayın | CVE-2007-6016Silahlaştırılmış | Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the symantec · backup exec for windows server · CWE-119 | Kritik9,3 | — | %50,4 | 29 Şub 2008 |
52Planlayın | CVE-2011-3478Kavram kanıtı | The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7symantec · pcanywhere · CWE-287 | Kritik10,0 | — | %39,5 | 25 Oca 2012 |
51Planlayın | CVE-2015-1486Silahlaştırılmış | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authenticatsymantec · endpoint protection manager · CWE-287 | Yüksek7,5 | — | %68,3 | 31 Tem 2015 |
51Planlayın | CVE-2009-3031Silahlaştırılmış | Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSCosymantec · altiris deployment solution · CWE-119 | Kritik9,3 | — | %45,4 | 3 Kas 2009 |
50Planlayın | CVE-2013-5014Silahlaştırılmış | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantesymantec · endpoint protection manager | Yüksek7,5 | — | %67,6 | 14 Şub 2014 |
50Planlayın | CVE-2004-0363Silahlaştırılmış | Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Securitsymantec · norton antispam | Yüksek7,5 | — | %66,6 | 15 Nis 2004 |
49Planlayın | CVE-2009-3033Silahlaştırılmış | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web consymantec · altiris deployment solution · CWE-119 | Kritik9,3 | — | %40,0 | 25 Kas 2009 |
48Planlayın | CVE-2008-4388Silahlaştırılmış | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly valsymantec · appstream client · CWE-20 | Kritik9,3 | — | %37,7 | 20 Oca 2009 |
47Planlayın | CVE-2012-1456İstismar yok | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Orta4,3 | — | %99,9 | 21 Mar 2012 |
47Planlayın | CVE-2012-1459İstismar yok | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Orta4,3 | — | %99,8 | 21 Mar 2012 |
47Planlayın | CVE-2012-1446İstismar yok | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Orta4,3 | — | %99,7 | 21 Mar 2012 |
47Planlayın | CVE-2012-1443İstismar yok | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Orta4,3 | — | %99,6 | 21 Mar 2012 |
47Planlayın | CVE-2016-2211İstismar yok | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 symantec · mail security for microsoft exchange · CWE-119 | Yüksek7,8 | — | %53,4 | 30 Haz 2016 |
47Planlayın | CVE-2010-0111Silahlaştırılmış | HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as symantec · antivirus · CWE-20 | Kritik9,3 | — | %34,5 | 31 Oca 2011 |
46Planlayın | CVE-2012-1457İstismar yok | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.anti-virus · vba32 · CWE-264 | Orta4,3 | — | %98,3 | 21 Mar 2012 |
46Planlayın | CVE-2012-1462İstismar yok | The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoftahnlab · v3 internet security · CWE-264 | Orta4,3 | — | %97,8 | 21 Mar 2012 |
- CVE-2017-632776Bu hafta
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %36symantec · message gateway11 Ağu 2017
- CVE-2009-142966Bu hafta
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec An
KritikCVSS 10,0SilahlaştırılmışEPSS %88symantec · antivirus29 Nis 2009
- CVE-2006-263062Bu hafta
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown
KritikCVSS 10,0SilahlaştırılmışEPSS %74symantec · client security27 May 2006
- CVE-2012-029762Bu hafta
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote
KritikCVSS 10,0SilahlaştırılmışEPSS %73symantec · web gateway21 May 2012
- CVE-2017-632662Bu hafta
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain
KritikCVSS 10,0SilahlaştırılmışEPSS %73symantec · messaging gateway26 Haz 2017
- CVE-2012-295360Bu hafta
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input
KritikCVSS 10,0SilahlaştırılmışEPSS %67symantec · web gateway23 Tem 2012
- CVE-2007-168960Bu hafta
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows re
KritikCVSS 10,0SilahlaştırılmışEPSS %65symantec · norton internet security16 May 2007
- CVE-2012-029959Planlayın
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code
KritikCVSS 10,0SilahlaştırılmışEPSS %64symantec · web gateway21 May 2012
- CVE-2009-143054Planlayın
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used
KritikCVSS 9,3SilahlaştırılmışEPSS %55symantec · antivirus29 Nis 2009
- CVE-2007-601652Planlayın
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the
KritikCVSS 9,3SilahlaştırılmışEPSS %50symantec · backup exec for windows server29 Şub 2008
- CVE-2011-347852Planlayın
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7
KritikCVSS 10,0Kavram kanıtıEPSS %40symantec · pcanywhere25 Oca 2012
- CVE-2015-148651Planlayın
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authenticat
YüksekCVSS 7,5SilahlaştırılmışEPSS %68symantec · endpoint protection manager31 Tem 2015
- CVE-2009-303151Planlayın
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSCo
KritikCVSS 9,3SilahlaştırılmışEPSS %45symantec · altiris deployment solution3 Kas 2009
- CVE-2013-501450Planlayın
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symante
YüksekCVSS 7,5SilahlaştırılmışEPSS %68symantec · endpoint protection manager14 Şub 2014
- CVE-2004-036350Planlayın
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Securit
YüksekCVSS 7,5SilahlaştırılmışEPSS %67symantec · norton antispam15 Nis 2004
- CVE-2009-303349Planlayın
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web con
KritikCVSS 9,3SilahlaştırılmışEPSS %40symantec · altiris deployment solution25 Kas 2009
- CVE-2008-438848Planlayın
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly val
KritikCVSS 9,3SilahlaştırılmışEPSS %38symantec · appstream client20 Oca 2009
- CVE-2012-145647Planlayın
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
OrtaCVSS 4,3İstismar yokEPSS %100avg · avg anti-virus21 Mar 2012
- CVE-2012-145947Planlayın
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
OrtaCVSS 4,3İstismar yokEPSS %100ahnlab · v3 internet security21 Mar 2012
- CVE-2012-144647Planlayın
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
OrtaCVSS 4,3İstismar yokEPSS %100ca · etrust vet antivirus21 Mar 2012
- CVE-2012-144347Planlayın
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
OrtaCVSS 4,3İstismar yokEPSS %100cat · quick heal21 Mar 2012
- CVE-2016-221147Planlayın
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6
YüksekCVSS 7,8İstismar yokEPSS %53symantec · mail security for microsoft exchange30 Haz 2016
- CVE-2010-011147Planlayın
HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as
KritikCVSS 9,3SilahlaştırılmışEPSS %35symantec · antivirus31 Oca 2011
- CVE-2012-145746Planlayın
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.
OrtaCVSS 4,3İstismar yokEPSS %98anti-virus · vba3221 Mar 2012
- CVE-2012-146246Planlayın
The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft
OrtaCVSS 4,3İstismar yokEPSS %98ahnlab · v3 internet security21 Mar 2012