Vulnerabilities > Symantec

DATE CVE VULNERABILITY TITLE RISK
2001-10-05 CVE-2001-1126 Unspecified vulnerability in Symantec Liveupdate 1.4/1.5/1.6
Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.
network
low complexity
symantec
5.0
2001-10-05 CVE-2001-1125 Download of Code Without Integrity Check vulnerability in Symantec Liveupdate 1.0/1.4/1.5
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
network
low complexity
symantec CWE-494
critical
9.8
2001-09-07 CVE-2001-1099 Unrestricted Upload of File With Dangerous Type vulnerability in Symantec Norton Antivirus 2.5
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
network
low complexity
symantec microsoft CWE-434
5.0
2001-08-14 CVE-2001-0549 Local Security vulnerability in Symantec Liveupdate 1.5
Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.
local
low complexity
symantec
4.6
2001-08-02 CVE-2001-0598 Unspecified vulnerability in Symantec Norton Ghost
Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled.
network
low complexity
symantec
5.0
2001-06-18 CVE-2001-0483 Unspecified vulnerability in Symantec Raptor Firewall 6.5
Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.
network
low complexity
symantec
7.5
2000-12-11 CVE-2000-1007 Unspecified vulnerability in Symantec I-Gear 3.5/3.5.7
I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.
network
low complexity
symantec
5.0
2000-06-14 CVE-2000-0478 Unspecified vulnerability in Symantec Norton Antivirus 1.5/2.0
In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server.
network
low complexity
symantec
5.0
2000-06-14 CVE-2000-0477 Unspecified vulnerability in Symantec Norton Antivirus 1.5/2.0
Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.
network
low complexity
symantec
5.0
2000-04-09 CVE-2000-0273 Unspecified vulnerability in Symantec Pcanywhere 8.0/9.0
PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.
network
low complexity
symantec
5.0