Vulnerabilities > Symantec > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-04 CVE-2022-25623 Unspecified vulnerability in Symantec Management Agent 8.5/8.6
The Symantec Management Agent is susceptible to a privilege escalation vulnerability.
local
low complexity
symantec
7.8
2019-12-11 CVE-2019-18379 Server-Side Request Forgery (SSRF) vulnerability in Symantec Messaging Gateway
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through the loopback interface.
network
low complexity
symantec CWE-918
7.5
2019-11-15 CVE-2019-18372 Unspecified vulnerability in Symantec Endpoint Protection 11/11.0/11.0.1
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
local
low complexity
symantec
7.2
2019-11-15 CVE-2019-12759 Unspecified vulnerability in Symantec Endpoint Protection Manager and Mail Security
Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
local
low complexity
symantec
7.2
2019-11-15 CVE-2019-12758 Uncontrolled Search Path Element vulnerability in Symantec Endpoint Protection 11/11.0/11.0.1
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.
local
low complexity
symantec CWE-427
7.2
2019-07-11 CVE-2019-12751 Unspecified vulnerability in Symantec Message Gateway
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
network
low complexity
symantec
7.5
2019-03-29 CVE-2019-9695 Code Injection vulnerability in Symantec Norton Core Firmware
Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that has the potential of allowing an individual to execute arbitrary commands or code on a target machine or in a target process.
local
low complexity
symantec CWE-94
7.2
2019-01-24 CVE-2018-18363 Unspecified vulnerability in Symantec Norton APP Lock
Norton App Lock prior to 1.4.0.445 can be susceptible to a bypass exploit.
local
low complexity
symantec
7.2
2018-09-19 CVE-2018-12242 Improper Authentication vulnerability in Symantec Messaging Gateway
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
network
low complexity
symantec CWE-287
7.5
2018-07-16 CVE-2018-5239 Unspecified vulnerability in Symantec Norton APP Lock
Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit.
local
low complexity
symantec
7.2