Vulnerabilities > Symantec > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-02-28 | CVE-2008-0309 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Symantec products Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp). | 6.8 |
2008-02-12 | CVE-2008-0716 | Privilege Escalation vulnerability in Symantec Altiris Notification Server Agents Shatter Attack The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack. | 6.8 |
2007-11-29 | CVE-2007-4346 | Resource Management Errors vulnerability in Symantec Backupexec System Recovery 11.0.6235/11.0.7170 The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (NULL dereference and service crash) via a crafted packet to port 5633/tcp. | 5.0 |
2007-11-05 | CVE-2007-5829 | Permissions, Privileges, and Access Controls vulnerability in Symantec Norton Antivirus and Norton Internet Security The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled. | 6.0 |
2007-11-03 | CVE-2007-5796 | Cross-Site Scripting vulnerability in Symantec Proxysg Firmware 5.0.0 Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists. | 4.3 |
2007-10-18 | CVE-2007-5555 | Information Exposure vulnerability in Symantec Altiris Deployment Solution 6 Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solution." NOTE: this description is based on a vague pre-advisory with no actionable information. | 6.9 |
2007-08-09 | CVE-2007-2955 | Remote Code Execution vulnerability in Symantec products Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly property to AxSysListView32OAA. network symantec | 6.8 |
2007-07-16 | CVE-2007-3800 | Local Privilege Escalation vulnerability in Symantec Client Security and Norton Antivirus Unspecified vulnerability in the Real-time scanner (RTVScan) component in Symantec AntiVirus Corporate Edition 9.0 through 10.1 and Client Security 2.0 through 3.1, when the Notification Message window is enabled, allows local users to gain privileges via crafted code. | 6.0 |
2007-07-15 | CVE-2007-3771 | Stack Overflow vulnerability in Symantec Client Security and Norton Antivirus Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. | 4.6 |
2007-07-15 | CVE-2007-3673 | Local Privilege Escalation vulnerability in Symantec Device Driver SYMTDI.SYS Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite. local symantec | 6.9 |