Vulnerabilities > Symantec > Endpoint Protection > 11.0.6200

DATE CVE VULNERABILITY TITLE RISK
2012-05-23 CVE-2012-0289 Buffer Errors vulnerability in Symantec Endpoint Protection and Network Access Control
Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.
local
low complexity
symantec CWE-119
7.2
2011-08-15 CVE-2011-0551 Cross-Site Request Forgery (CSRF) vulnerability in Symantec Endpoint Protection
Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
network
symantec CWE-352
6.8
2011-08-15 CVE-2011-0550 Cross-Site Scripting vulnerability in Symantec Endpoint Protection
Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token parameter to portal/Help.jsp or (2) the URI in a console/apps/sepm request.
network
symantec CWE-79
4.3