Vulnerabilities > Symantec
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-02-08 | CVE-2008-0640 | Improper Authentication vulnerability in Symantec Ghost Solutions Suite 1.1/2.0.0/2.0.1 Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing. | 10.0 |
2008-02-07 | CVE-2008-0457 | Improper Input Validation vulnerability in Symantec Backupexec System Recovery 7.0/7.01 Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors. | 10.0 |
2007-11-29 | CVE-2007-4347 | Numeric Errors vulnerability in Symantec Backupexec System Recovery 11.0.6235/11.0.7170 Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to cause a denial of service (CPU and memory consumption) via a crafted packet to port 5633/tcp, which triggers an infinite loop. | 7.8 |
2007-11-29 | CVE-2007-4346 | Resource Management Errors vulnerability in Symantec Backupexec System Recovery 11.0.6235/11.0.7170 The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a crafted packet to port 5633/tcp. | 5.0 |
2007-11-10 | CVE-2007-5910 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file. | 9.3 |
2007-11-10 | CVE-2007-5909 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. | 9.3 |
2007-11-06 | CVE-2007-5838 | Configuration vulnerability in Symantec Altiris Deployment Solution 6/6.8 Aclient in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows local users to gain local System privileges via the "Enable key-based authentication to Deployment server" browser option, a different issue than CVE-2007-4380. | 7.2 |
2007-11-05 | CVE-2007-5829 | Permissions, Privileges, and Access Controls vulnerability in Symantec Norton Antivirus and Norton Internet Security The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled. | 6.0 |
2007-11-03 | CVE-2007-5796 | Cross-Site Scripting vulnerability in Symantec Proxysg Firmware 5.0.0 Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists. | 4.3 |
2007-10-18 | CVE-2007-5555 | Information Exposure vulnerability in Symantec Altiris Deployment Solution 6 Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solution." NOTE: this description is based on a vague pre-advisory with no actionable information. | 6.9 |