Vulnerabilities > Symantec

DATE CVE VULNERABILITY TITLE RISK
2016-05-14 CVE-2015-8156 Unspecified vulnerability in Symantec Endpoint Encryption 11.0/11.0.0/11.0.1
Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
local
low complexity
symantec
7.8
2016-04-22 CVE-2016-2204 Injection vulnerability in Symantec Messaging Gateway 10.6.0
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.
local
low complexity
symantec CWE-74
8.2
2016-04-22 CVE-2016-2203 Credentials Management vulnerability in Symantec Messaging Gateway 10.6.0
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
local
low complexity
symantec CWE-255
7.8
2016-04-20 CVE-2016-2202 Permissions, Privileges, and Access Controls vulnerability in Symantec Altiris IT Management Suite 7.6
The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restrictions via unspecified vectors.
local
low complexity
symantec CWE-264
5.5
2016-03-18 CVE-2015-8154 Permissions, Privileges, and Access Controls vulnerability in Symantec Endpoint Protection Manager
The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions."
network
low complexity
symantec CWE-264
8.8
2016-03-18 CVE-2015-8153 SQL Injection vulnerability in Symantec Endpoint Protection Manager
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
symantec CWE-89
8.8
2016-03-18 CVE-2015-8152 Cross-Site Request Forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager 12.1
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.
network
low complexity
symantec CWE-352
8.0
2016-02-18 CVE-2015-8151 OS Command Injection vulnerability in Symantec Encryption Management Server 3.3.2
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.
network
low complexity
symantec CWE-78
critical
9.1
2016-02-18 CVE-2015-8150 Permissions, Privileges, and Access Controls vulnerability in Symantec Encryption Management Server 3.3.2
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.
local
low complexity
symantec CWE-264
7.8
2016-02-18 CVE-2015-8149 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Symantec Encryption Management Server 3.3.2
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests.
network
low complexity
symantec CWE-119
7.5