Vulnerabilities > Symantec > Norton Antivirus > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-10-05 CVE-2007-3699 Remote vulnerability in Symantec AntiVirus Malformed CAB and RAR Compression
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
network
symantec
critical
9.3
2007-06-06 CVE-2007-3095 Authentication Bypass vulnerability in Symantec Client Security, Norton Antivirus and Reporting Server
Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown vectors.
network
low complexity
symantec
critical
9.0
2007-02-22 CVE-2006-6490 Remote Buffer Overflow vulnerability in SupportSoft ActiveX Controls
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
network
low complexity
supportsoft symantec
critical
10.0
2006-05-27 CVE-2006-2630 Remote Stack Buffer Overflow vulnerability in Symantec Client Security and Norton Antivirus
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.
network
low complexity
symantec
critical
10.0
2005-08-30 CVE-2005-2017 Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1000
Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.
network
low complexity
symantec
critical
10.0
2004-08-18 CVE-2004-0487 Remote Code Execution vulnerability in Symantec Norton Antivirus 2.1
A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.
network
low complexity
symantec
critical
10.0