Vulnerabilities > Symantec > Norton 360

DATE CVE VULNERABILITY TITLE RISK
2009-04-29 CVE-2009-1428 Cross-Site Scripting vulnerability in Symantec products
Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to "two parsing errors."
network
symantec CWE-79
4.3
2008-04-08 CVE-2008-0313 Remote Share 'launchProcess()' Insecure Method vulnerability in Symantec AutoFix Tool ActiveX Control
The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share.
network
symantec
6.8
2008-04-08 CVE-2008-0312 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Symantec products
Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogInfo method.
network
microsoft symantec CWE-119
critical
9.3
2007-04-02 CVE-2007-1793 Improper Input Validation vulnerability in Symantec products
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions.
local
low complexity
symantec CWE-20
4.9