Vulnerabilities > Symantec > Client Security > High

DATE CVE VULNERABILITY TITLE RISK
2007-06-05 CVE-2007-3021 Remote Privilege Escalation vulnerability in Symantec Client Security, Norton Antivirus and Reporting Server
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations of a file that is created during data export.
network
low complexity
symantec
7.5
2006-09-14 CVE-2006-3454 Local Format String vulnerability in Symantec Client Security and Norton Antivirus
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
local
low complexity
symantec
7.2
2005-02-08 CVE-2005-0249 Unspecified vulnerability in Symantec products
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
network
low complexity
symantec
7.5