Vulnerabilities > Symantec > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0817 Unspecified vulnerability in Symantec products
Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.
network
low complexity
symantec
5.0
2005-05-02 CVE-2005-0618 The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted network.
network
low complexity
nexland symantec
6.4
2004-12-31 CVE-2004-2755 Cross-Site Scripting vulnerability in Symantec web Security 2.5/3.0/3.0.1
Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page messages.
network
symantec CWE-79
4.3
2004-12-31 CVE-2004-2147 Denial Of Service vulnerability in Symantec Norton AntiVirus Malformed EMail
Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
network
low complexity
symantec
5.0
2004-12-31 CVE-2004-1910 Denial Of Service vulnerability in Symantec Security Check Virus Detection COM Object
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function.
network
low complexity
symantec
5.0
2004-12-31 CVE-2004-1474 Remote vulnerability in Symantec Enterprise Firewall/VPN Appliance
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.
network
low complexity
symantec
5.0
2004-12-31 CVE-2004-1473 Remote vulnerability in Symantec Enterprise Firewall/VPN Appliance
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.
network
low complexity
symantec
5.0
2004-12-31 CVE-2004-1472 Remote vulnerability in Symantec Enterprise Firewall/VPN Appliance
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.
network
low complexity
symantec
5.0
2004-12-17 CVE-2004-1768 Unspecified vulnerability in Symantec Brightmail Antispam 6.0.1
The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters.
network
low complexity
symantec
5.0
2004-11-23 CVE-2004-0081 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. 5.0