Symantec records
571 published records for vendor symantec.
Researcher profile
- Entered KEV
- 1 · 0.2%
- Weaponized
- 27 · 4.7%
- Pre-auth RCE
- 96
- With a fix record
- 0.9%
- Median publish → KEV
- 1545 days
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls47
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer42
- CWE-20 Improper Input Validation30
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor22
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')21
The weakness classes this vendor ships most often: where to look.
CWEAll records
571 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2017-6327Weaponized | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an indsymantec · message gateway · CWE-77 | High8.8 | KEV | 35.9% | Aug 11, 2017 |
66This week | CVE-2009-1429Weaponized | The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec Ansymantec · antivirus · CWE-94 | Critical10.0 | — | 87.7% | Apr 29, 2009 |
62This week | CVE-2006-2630Weaponized | Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknownsymantec · client security | Critical10.0 | — | 73.6% | May 27, 2006 |
62This week | CVE-2012-0297Weaponized | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote symantec · web gateway · CWE-264 | Critical10.0 | — | 73.0% | May 21, 2012 |
62This week | CVE-2017-6326Weaponized | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtainsymantec · messaging gateway | Critical10.0 | — | 72.8% | Jun 26, 2017 |
60This week | CVE-2012-2953Weaponized | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted inputsymantec · web gateway · CWE-78 | Critical10.0 | — | 67.4% | Jul 23, 2012 |
60This week | CVE-2007-1689Weaponized | Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows resymantec · norton internet security | Critical10.0 | — | 65.0% | May 16, 2007 |
59Plan | CVE-2012-0299Weaponized | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codesymantec · web gateway · CWE-264 | Critical10.0 | — | 63.7% | May 21, 2012 |
54Plan | CVE-2009-1430Weaponized | Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as usedsymantec · antivirus · CWE-119 | Critical9.3 | — | 55.1% | Apr 29, 2009 |
52Plan | CVE-2007-6016Weaponized | Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the symantec · backup exec for windows server · CWE-119 | Critical9.3 | — | 50.4% | Feb 29, 2008 |
52Plan | CVE-2011-3478Proof of concept | The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7symantec · pcanywhere · CWE-287 | Critical10.0 | — | 39.5% | Jan 25, 2012 |
51Plan | CVE-2015-1486Weaponized | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authenticatsymantec · endpoint protection manager · CWE-287 | High7.5 | — | 68.3% | Jul 31, 2015 |
51Plan | CVE-2009-3031Weaponized | Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSCosymantec · altiris deployment solution · CWE-119 | Critical9.3 | — | 45.4% | Nov 3, 2009 |
50Plan | CVE-2013-5014Weaponized | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantesymantec · endpoint protection manager | High7.5 | — | 67.6% | Feb 14, 2014 |
50Plan | CVE-2004-0363Weaponized | Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Securitsymantec · norton antispam | High7.5 | — | 66.6% | Apr 15, 2004 |
49Plan | CVE-2009-3033Weaponized | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web consymantec · altiris deployment solution · CWE-119 | Critical9.3 | — | 40.0% | Nov 25, 2009 |
48Plan | CVE-2008-4388Weaponized | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly valsymantec · appstream client · CWE-20 | Critical9.3 | — | 37.7% | Jan 20, 2009 |
47Plan | CVE-2012-1456No exploit | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Medium4.3 | — | 99.9% | Mar 21, 2012 |
47Plan | CVE-2012-1459No exploit | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 99.8% | Mar 21, 2012 |
47Plan | CVE-2012-1446No exploit | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Medium4.3 | — | 99.7% | Mar 21, 2012 |
47Plan | CVE-2012-1443No exploit | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Medium4.3 | — | 99.6% | Mar 21, 2012 |
47Plan | CVE-2016-2211No exploit | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 symantec · mail security for microsoft exchange · CWE-119 | High7.8 | — | 53.4% | Jun 30, 2016 |
47Plan | CVE-2010-0111Weaponized | HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as symantec · antivirus · CWE-20 | Critical9.3 | — | 34.5% | Jan 31, 2011 |
46Plan | CVE-2012-1457No exploit | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.anti-virus · vba32 · CWE-264 | Medium4.3 | — | 98.3% | Mar 21, 2012 |
46Plan | CVE-2012-1462No exploit | The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoftahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 97.8% | Mar 21, 2012 |
- CVE-2017-632776This week
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind
HighCVSS 8.8KEVWeaponizedEPSS 36%symantec · message gatewayAug 11, 2017
- CVE-2009-142966This week
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec An
CriticalCVSS 10.0WeaponizedEPSS 88%symantec · antivirusApr 29, 2009
- CVE-2006-263062This week
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown
CriticalCVSS 10.0WeaponizedEPSS 74%symantec · client securityMay 27, 2006
- CVE-2012-029762This week
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote
CriticalCVSS 10.0WeaponizedEPSS 73%symantec · web gatewayMay 21, 2012
- CVE-2017-632662This week
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain
CriticalCVSS 10.0WeaponizedEPSS 73%symantec · messaging gatewayJun 26, 2017
- CVE-2012-295360This week
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input
CriticalCVSS 10.0WeaponizedEPSS 67%symantec · web gatewayJul 23, 2012
- CVE-2007-168960This week
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows re
CriticalCVSS 10.0WeaponizedEPSS 65%symantec · norton internet securityMay 16, 2007
- CVE-2012-029959Plan
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code
CriticalCVSS 10.0WeaponizedEPSS 64%symantec · web gatewayMay 21, 2012
- CVE-2009-143054Plan
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used
CriticalCVSS 9.3WeaponizedEPSS 55%symantec · antivirusApr 29, 2009
- CVE-2007-601652Plan
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the
CriticalCVSS 9.3WeaponizedEPSS 50%symantec · backup exec for windows serverFeb 29, 2008
- CVE-2011-347852Plan
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7
CriticalCVSS 10.0Proof of conceptEPSS 40%symantec · pcanywhereJan 25, 2012
- CVE-2015-148651Plan
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authenticat
HighCVSS 7.5WeaponizedEPSS 68%symantec · endpoint protection managerJul 31, 2015
- CVE-2009-303151Plan
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSCo
CriticalCVSS 9.3WeaponizedEPSS 45%symantec · altiris deployment solutionNov 3, 2009
- CVE-2013-501450Plan
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symante
HighCVSS 7.5WeaponizedEPSS 68%symantec · endpoint protection managerFeb 14, 2014
- CVE-2004-036350Plan
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Securit
HighCVSS 7.5WeaponizedEPSS 67%symantec · norton antispamApr 15, 2004
- CVE-2009-303349Plan
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web con
CriticalCVSS 9.3WeaponizedEPSS 40%symantec · altiris deployment solutionNov 25, 2009
- CVE-2008-438848Plan
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly val
CriticalCVSS 9.3WeaponizedEPSS 38%symantec · appstream clientJan 20, 2009
- CVE-2012-145647Plan
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
MediumCVSS 4.3No exploitEPSS 100%avg · avg anti-virusMar 21, 2012
- CVE-2012-145947Plan
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
MediumCVSS 4.3No exploitEPSS 100%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-144647Plan
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
MediumCVSS 4.3No exploitEPSS 100%ca · etrust vet antivirusMar 21, 2012
- CVE-2012-144347Plan
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
MediumCVSS 4.3No exploitEPSS 100%cat · quick healMar 21, 2012
- CVE-2016-221147Plan
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6
HighCVSS 7.8No exploitEPSS 53%symantec · mail security for microsoft exchangeJun 30, 2016
- CVE-2010-011147Plan
HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as
CriticalCVSS 9.3WeaponizedEPSS 35%symantec · antivirusJan 31, 2011
- CVE-2012-145746Plan
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.
MediumCVSS 4.3No exploitEPSS 98%anti-virus · vba32Mar 21, 2012
- CVE-2012-146246Plan
The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft
MediumCVSS 4.3No exploitEPSS 98%ahnlab · v3 internet securityMar 21, 2012