Vulnerabilities > Symantec

DATE CVE VULNERABILITY TITLE RISK
2019-11-15 CVE-2019-12756 Unspecified vulnerability in Symantec Endpoint Protection
Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights.
local
low complexity
symantec
2.1
2019-11-15 CVE-2018-18368 Improper Privilege Management vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
local
low complexity
symantec CWE-269
4.6
2019-11-01 CVE-2019-12752 Incorrect Default Permissions vulnerability in Symantec Sonar
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.
low complexity
symantec CWE-276
4.1
2019-10-24 CVE-2019-9699 Information Exposure vulnerability in Symantec Messaging Gateway
Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.
low complexity
symantec CWE-200
2.7
2019-09-17 CVE-2019-12755 Information Exposure vulnerability in Symantec Norton Password Manager
Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.
local
low complexity
symantec CWE-200
2.1
2019-08-30 CVE-2019-9697 Information Exposure vulnerability in Symantec Management Center 2.0/2.1/2.2
An information disclosure vulnerability in the Management Center (MC) REST API 2.0, 2.1, and 2.2 prior to 2.2.2.1 allows a malicious authenticated user to obtain passwords for external backup and CPL policy import servers that they might not otherwise be authorized to access.
network
low complexity
symantec CWE-200
4.0
2019-08-30 CVE-2019-12754 Cross-site Scripting vulnerability in Symantec VIP
Symantec My VIP portal, previous version which has already been auto updated, was susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users or potentially bypass access controls such as the same-origin policy.
network
symantec CWE-79
3.5
2019-08-30 CVE-2019-12753 Information Exposure vulnerability in Symantec Reporter 10.3/10.3.1.1/10.3.2.1
An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authenticated administrator user to obtain passwords for external SMTP, FTP, FTPS, LDAP, and Cloud Log Download servers that they might not otherwise be authorized to access.
network
low complexity
symantec CWE-200
4.0
2019-07-31 CVE-2019-12750 Out-of-bounds Read vulnerability in Symantec Endpoint Protection
Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
local
low complexity
symantec CWE-125
4.6
2019-07-11 CVE-2019-12751 Unspecified vulnerability in Symantec Message Gateway
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
network
low complexity
symantec
7.5