Записи Symantec
571 опубликованных записей вендора symantec.
Профиль для исследователя
- Попали в KEV
- 1 · 0,2 %
- С эксплойтом
- 27 · 4,7 %
- Pre-auth RCE
- 96
- С записью об исправлении
- 0,9 %
- Медиана: публикация → KEV
- 1545 дн.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls47
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer42
- CWE-20 Improper Input Validation30
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor22
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')21
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
571 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
76На этой неделе | CVE-2017-6327Готовый эксплойт | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an indsymantec · message gateway · CWE-77 | Высокая8,8 | KEV | 35,9 % | 11 авг. 2017 г. |
66На этой неделе | CVE-2009-1429Готовый эксплойт | The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec Ansymantec · antivirus · CWE-94 | Критическая10,0 | — | 87,7 % | 29 апр. 2009 г. |
62На этой неделе | CVE-2006-2630Готовый эксплойт | Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknownsymantec · client security | Критическая10,0 | — | 73,6 % | 27 мая 2006 г. |
62На этой неделе | CVE-2012-0297Готовый эксплойт | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote symantec · web gateway · CWE-264 | Критическая10,0 | — | 73,0 % | 21 мая 2012 г. |
62На этой неделе | CVE-2017-6326Готовый эксплойт | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtainsymantec · messaging gateway | Критическая10,0 | — | 72,8 % | 26 июн. 2017 г. |
60На этой неделе | CVE-2012-2953Готовый эксплойт | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted inputsymantec · web gateway · CWE-78 | Критическая10,0 | — | 67,4 % | 23 июл. 2012 г. |
60На этой неделе | CVE-2007-1689Готовый эксплойт | Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows resymantec · norton internet security | Критическая10,0 | — | 65,0 % | 16 мая 2007 г. |
59В плане | CVE-2012-0299Готовый эксплойт | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codesymantec · web gateway · CWE-264 | Критическая10,0 | — | 63,7 % | 21 мая 2012 г. |
54В плане | CVE-2009-1430Готовый эксплойт | Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as usedsymantec · antivirus · CWE-119 | Критическая9,3 | — | 55,1 % | 29 апр. 2009 г. |
52В плане | CVE-2007-6016Готовый эксплойт | Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the symantec · backup exec for windows server · CWE-119 | Критическая9,3 | — | 50,4 % | 29 февр. 2008 г. |
52В плане | CVE-2011-3478Proof of concept | The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7symantec · pcanywhere · CWE-287 | Критическая10,0 | — | 39,5 % | 25 янв. 2012 г. |
51В плане | CVE-2015-1486Готовый эксплойт | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authenticatsymantec · endpoint protection manager · CWE-287 | Высокая7,5 | — | 68,3 % | 31 июл. 2015 г. |
51В плане | CVE-2009-3031Готовый эксплойт | Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSCosymantec · altiris deployment solution · CWE-119 | Критическая9,3 | — | 45,4 % | 3 нояб. 2009 г. |
50В плане | CVE-2013-5014Готовый эксплойт | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantesymantec · endpoint protection manager | Высокая7,5 | — | 67,6 % | 14 февр. 2014 г. |
50В плане | CVE-2004-0363Готовый эксплойт | Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Securitsymantec · norton antispam | Высокая7,5 | — | 66,6 % | 15 апр. 2004 г. |
49В плане | CVE-2009-3033Готовый эксплойт | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web consymantec · altiris deployment solution · CWE-119 | Критическая9,3 | — | 40,0 % | 25 нояб. 2009 г. |
48В плане | CVE-2008-4388Готовый эксплойт | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly valsymantec · appstream client · CWE-20 | Критическая9,3 | — | 37,7 % | 20 янв. 2009 г. |
47В плане | CVE-2012-1456Эксплойта нет | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Средняя4,3 | — | 99,9 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1459Эксплойта нет | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Средняя4,3 | — | 99,8 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1446Эксплойта нет | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Средняя4,3 | — | 99,7 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1443Эксплойта нет | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Средняя4,3 | — | 99,6 % | 21 мар. 2012 г. |
47В плане | CVE-2016-2211Эксплойта нет | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 symantec · mail security for microsoft exchange · CWE-119 | Высокая7,8 | — | 53,4 % | 30 июн. 2016 г. |
47В плане | CVE-2010-0111Готовый эксплойт | HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as symantec · antivirus · CWE-20 | Критическая9,3 | — | 34,5 % | 31 янв. 2011 г. |
46В плане | CVE-2012-1457Эксплойта нет | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.anti-virus · vba32 · CWE-264 | Средняя4,3 | — | 98,3 % | 21 мар. 2012 г. |
46В плане | CVE-2012-1462Эксплойта нет | The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoftahnlab · v3 internet security · CWE-264 | Средняя4,3 | — | 97,8 % | 21 мар. 2012 г. |
- CVE-2017-632776На этой неделе
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 36 %symantec · message gateway11 авг. 2017 г.
- CVE-2009-142966На этой неделе
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec An
КритическаяCVSS 10,0Готовый эксплойтEPSS 88 %symantec · antivirus29 апр. 2009 г.
- CVE-2006-263062На этой неделе
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %symantec · client security27 мая 2006 г.
- CVE-2012-029762На этой неделе
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote
КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %symantec · web gateway21 мая 2012 г.
- CVE-2017-632662На этой неделе
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain
КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %symantec · messaging gateway26 июн. 2017 г.
- CVE-2012-295360На этой неделе
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input
КритическаяCVSS 10,0Готовый эксплойтEPSS 67 %symantec · web gateway23 июл. 2012 г.
- CVE-2007-168960На этой неделе
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows re
КритическаяCVSS 10,0Готовый эксплойтEPSS 65 %symantec · norton internet security16 мая 2007 г.
- CVE-2012-029959В плане
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code
КритическаяCVSS 10,0Готовый эксплойтEPSS 64 %symantec · web gateway21 мая 2012 г.
- CVE-2009-143054В плане
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used
КритическаяCVSS 9,3Готовый эксплойтEPSS 55 %symantec · antivirus29 апр. 2009 г.
- CVE-2007-601652В плане
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the
КритическаяCVSS 9,3Готовый эксплойтEPSS 50 %symantec · backup exec for windows server29 февр. 2008 г.
- CVE-2011-347852В плане
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7
КритическаяCVSS 10,0Proof of conceptEPSS 40 %symantec · pcanywhere25 янв. 2012 г.
- CVE-2015-148651В плане
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authenticat
ВысокаяCVSS 7,5Готовый эксплойтEPSS 68 %symantec · endpoint protection manager31 июл. 2015 г.
- CVE-2009-303151В плане
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSCo
КритическаяCVSS 9,3Готовый эксплойтEPSS 45 %symantec · altiris deployment solution3 нояб. 2009 г.
- CVE-2013-501450В плане
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symante
ВысокаяCVSS 7,5Готовый эксплойтEPSS 68 %symantec · endpoint protection manager14 февр. 2014 г.
- CVE-2004-036350В плане
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Securit
ВысокаяCVSS 7,5Готовый эксплойтEPSS 67 %symantec · norton antispam15 апр. 2004 г.
- CVE-2009-303349В плане
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web con
КритическаяCVSS 9,3Готовый эксплойтEPSS 40 %symantec · altiris deployment solution25 нояб. 2009 г.
- CVE-2008-438848В плане
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly val
КритическаяCVSS 9,3Готовый эксплойтEPSS 38 %symantec · appstream client20 янв. 2009 г.
- CVE-2012-145647В плане
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
СредняяCVSS 4,3Эксплойта нетEPSS 100 %avg · avg anti-virus21 мар. 2012 г.
- CVE-2012-145947В плане
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
СредняяCVSS 4,3Эксплойта нетEPSS 100 %ahnlab · v3 internet security21 мар. 2012 г.
- CVE-2012-144647В плане
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
СредняяCVSS 4,3Эксплойта нетEPSS 100 %ca · etrust vet antivirus21 мар. 2012 г.
- CVE-2012-144347В плане
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
СредняяCVSS 4,3Эксплойта нетEPSS 100 %cat · quick heal21 мар. 2012 г.
- CVE-2016-221147В плане
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6
ВысокаяCVSS 7,8Эксплойта нетEPSS 53 %symantec · mail security for microsoft exchange30 июн. 2016 г.
- CVE-2010-011147В плане
HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as
КритическаяCVSS 9,3Готовый эксплойтEPSS 35 %symantec · antivirus31 янв. 2011 г.
- CVE-2012-145746В плане
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.
СредняяCVSS 4,3Эксплойта нетEPSS 98 %anti-virus · vba3221 мар. 2012 г.
- CVE-2012-146246В плане
The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft
СредняяCVSS 4,3Эксплойта нетEPSS 98 %ahnlab · v3 internet security21 мар. 2012 г.