Vulnerabilities > Symantec > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-23958 Unspecified vulnerability in Symantec Protection Engine
Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
network
low complexity
symantec
6.5
2023-09-19 CVE-2023-23957 Open Redirect vulnerability in Symantec Identity Portal 14.4
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
network
low complexity
symantec CWE-601
5.4
2022-12-09 CVE-2022-25629 Cross-site Scripting vulnerability in Symantec Messaging Gateway
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
network
low complexity
symantec CWE-79
5.4
2022-12-09 CVE-2022-25630 Cross-site Scripting vulnerability in Symantec Messaging Gateway
An authenticated user can embed malicious content with XSS into the admin group policy page.
network
low complexity
symantec CWE-79
5.4
2020-05-13 CVE-2020-5838 Cross-site Scripting vulnerability in Symantec IT Analytics
Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.
network
low complexity
symantec CWE-79
4.8
2020-05-11 CVE-2020-5834 Path Traversal vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow a remote actor to determine the size of files in the directory.
network
low complexity
symantec CWE-22
5.3
2020-04-10 CVE-2019-18376 Cross-Site Request Forgery (CSRF) vulnerability in Symantec Management Center 2.2/2.3/2.4
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.
network
high complexity
symantec CWE-352
5.9
2020-02-11 CVE-2020-5826 Out-of-bounds Read vulnerability in Symantec Endpoint Protection
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
local
low complexity
symantec CWE-125
5.5
2020-02-11 CVE-2020-5825 Unspecified vulnerability in Symantec Endpoint Protection
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the resident system without proper privileges.
local
low complexity
symantec
5.5
2020-02-11 CVE-2020-5824 Unspecified vulnerability in Symantec Endpoint Protection
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a denial of service vulnerability, which is a type of issue whereby a threat actor attempts to tie up the resources of a resident application, thereby making certain functions unavailable.
local
low complexity
symantec
5.5