Vulnerabilities > Symantec > Norton Antivirus > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-11-03 CVE-2004-0920 Unspecified vulnerability in Symantec Norton Antivirus
Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.
network
low complexity
symantec
5.0
2004-08-06 CVE-2004-0683 Denial-Of-Service vulnerability in Norton AntiVirus 2003 Professional Edition
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.
network
low complexity
symantec
5.0
2003-12-31 CVE-2003-1451 Buffer Errors vulnerability in Symantec Norton Antivirus 2002
Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.
network
low complexity
symantec CWE-119
6.4
2003-12-31 CVE-2003-1310 Unspecified vulnerability in Symantec Norton Antivirus 2002/2003
The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").
local
low complexity
symantec
4.6
2001-09-07 CVE-2001-1099 Unrestricted Upload of File With Dangerous Type vulnerability in Symantec Norton Antivirus 2.5
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
network
low complexity
symantec microsoft CWE-434
5.0
2000-06-14 CVE-2000-0478 Unspecified vulnerability in Symantec Norton Antivirus 1.5/2.0
In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server.
network
low complexity
symantec
5.0
2000-06-14 CVE-2000-0477 Unspecified vulnerability in Symantec Norton Antivirus 1.5/2.0
Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.
network
low complexity
symantec
5.0
1999-04-09 CVE-1999-1323 Unspecified vulnerability in Symantec Norton Antivirus
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.
local
low complexity
symantec
4.6