Vulnerabilities > Symantec > Norton Save AND Recovery

DATE CVE VULNERABILITY TITLE RISK
2007-04-30 CVE-2007-2361 Local Security vulnerability in BackupExec System Recovery
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.
local
low complexity
symantec
4.9
2007-04-30 CVE-2007-2360 Local Security vulnerability in BackupExec System Recovery
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.
local
low complexity
symantec
6.8
2007-04-30 CVE-2007-2359 Local Security vulnerability in BackupExec System Recovery
Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.
local
low complexity
symantec
7.2