Vulnerabilities > Symantec > Norton Antivirus > 10.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-09-19 | CVE-2006-4855 | Resource Management Errors vulnerability in Symantec products The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data. | 4.9 |
2006-09-14 | CVE-2006-3454 | Local Format String vulnerability in Symantec Client Security and Norton Antivirus Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages. | 7.2 |
2006-05-27 | CVE-2006-2630 | Remote Stack Buffer Overflow vulnerability in Symantec Client Security and Norton Antivirus Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors. | 10.0 |
2006-04-19 | CVE-2006-1836 | Local Privilege Escalation vulnerability in Symantec LiveUpdate for Macintosh Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | 6.8 |