Vulnerabilities > Symantec > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-08-07 CVE-2006-4014 Multiple vulnerability in Symantec Brightmail AntiSpam Control Center
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts".
network
low complexity
symantec
5.0
2006-06-19 CVE-2006-3072 Authentication Bypass vulnerability in Symantec Security Information Manager
M4 Macro Library in Symantec Security Information Manager before 4.0.2.29 HOTFIX 1 allows local users to execute arbitrary commands via crafted "rule definitions", which produces dangerous Java code during M4 transformation.
local
low complexity
symantec
4.6
2006-05-12 CVE-2006-2341 Information Exposure vulnerability in Symantec Enterprise Firewall and Gateway Security
The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI.
network
low complexity
symantec CWE-200
5.0
2006-04-25 CVE-2006-0232 Remote vulnerability in Symantec Antivirus Scan Engine 5.0.0.24
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.
network
low complexity
symantec
5.0
2006-04-25 CVE-2006-0231 Remote vulnerability in Symantec Antivirus Scan Engine 5.0.0.24
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.
network
low complexity
symantec
6.4
2006-04-19 CVE-2006-1836 Local Privilege Escalation vulnerability in Symantec LiveUpdate for Macintosh
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
local
low complexity
symantec
6.8
2006-03-19 CVE-2006-1284 Local Administrative Authentication Credentials Disclosure vulnerability in Symantec Ghost Solutions Suite and Norton Ghost
The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks.
local
low complexity
symantec
4.6
2005-12-31 CVE-2005-4695 Denial Of Service vulnerability in Symantec Brightmail Antispam 6.0/6.0.1/6.0.2
Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages.
network
low complexity
symantec
5.0
2005-10-14 CVE-2005-3217 Unspecified vulnerability in Symantec Antivirus Scan Engine
Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
symantec
5.1
2005-05-02 CVE-2005-0922 Remote Denial Of Service vulnerability in Symantec products
Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type.
network
low complexity
symantec
5.0