Vulnerabilities > Symantec > Low

DATE CVE VULNERABILITY TITLE RISK
2006-07-21 CVE-2006-3725 Denial-Of-Service vulnerability in Symantec Norton Personal Firewall 20069.1.0.33
Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc and (2) HKLM\SYSTEM\CurrentControlSet\Services\SymEvent registry keys.
local
low complexity
symantec
2.1
2006-03-19 CVE-2006-1285 Local Information Disclosure and Data Corruption vulnerability in Symantec Ghost Solutions Suite and Norton Ghost
SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information.
local
low complexity
symantec
3.2
2006-03-19 CVE-2006-1286 Information Disclosure vulnerability in Symantec Ghost Solutions Suite and Norton Ghost
Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database.
local
low complexity
symantec
2.1
2005-09-02 CVE-2005-2766 Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1.1000/9.0.4
Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.
local
low complexity
symantec
2.1
2005-05-02 CVE-2005-0923 Local Denial Of Service vulnerability in Symantec products
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share.
local
low complexity
symantec
2.1
2005-05-02 CVE-2005-1346 Denial-Of-Service vulnerability in Web Security
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid detection via a crafted RAR file.
network
high complexity
symantec
2.6
2004-12-31 CVE-2004-2609 Unspecified vulnerability in Symantec Powerquest Deploycenter 5.5
The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.
local
low complexity
symantec
2.1
2004-07-07 CVE-2004-0445 Remote DNS Response Denial Of Service vulnerability in Symantec Client Firewall
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.
network
high complexity
symantec
2.6