Lucene search

K

Norton Security Security Vulnerabilities

cve
cve

CVE-2006-4802

Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notification messages, a different vector than...

7.1AI Score

0.018EPSS

2006-09-14 10:07 PM
21
cve
cve

CVE-2006-3454

Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification...

7.3AI Score

0.001EPSS

2006-09-14 12:07 AM
24
cve
cve

CVE-2006-2630

Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack...

7.8AI Score

0.971EPSS

2006-05-27 09:02 PM
20
cve
cve

CVE-2006-1836

Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse...

6.6AI Score

0.001EPSS

2006-04-19 04:06 PM
19
cve
cve

CVE-2006-1286

Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the...

6.2AI Score

0.0004EPSS

2006-03-19 11:02 PM
22
cve
cve

CVE-2006-1285

SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain...

6.4AI Score

0.0004EPSS

2006-03-19 11:02 PM
18
cve
cve

CVE-2006-1284

The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify...

6.6AI Score

0.0004EPSS

2006-03-19 11:02 PM
27
cve
cve

CVE-2006-0166

Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other.....

6.8AI Score

0.014EPSS

2006-01-11 09:03 PM
24
cve
cve

CVE-2005-2759

** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use...

6.6AI Score

EPSS

2005-10-20 11:02 PM
22
cve
cve

CVE-2002-1695

Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is...

7AI Score

0.004EPSS

2005-06-21 04:00 AM
26
cve
cve

CVE-2002-1778

Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH...

7.1AI Score

0.004EPSS

2005-06-21 04:00 AM
23
cve
cve

CVE-2003-1149

Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error...

5.8AI Score

0.002EPSS

2005-05-10 04:00 AM
21
cve
cve

CVE-2005-0922

Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file...

6.5AI Score

0.002EPSS

2005-05-02 04:00 AM
26
cve
cve

CVE-2005-1346

Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote...

7AI Score

0.003EPSS

2005-05-02 04:00 AM
20
cve
cve

CVE-2005-0923

The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network...

6.5AI Score

0.001EPSS

2005-05-02 04:00 AM
18
cve
cve

CVE-2005-0249

Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE...

8AI Score

0.004EPSS

2005-02-08 05:00 AM
28
cve
cve

CVE-2004-0920

Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device...

6.8AI Score

0.001EPSS

2004-11-03 05:00 AM
22
cve
cve

CVE-2003-0994

The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain...

6.6AI Score

0.0004EPSS

2004-09-01 04:00 AM
29
cve
cve

CVE-2004-0375

SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate...

6.7AI Score

0.022EPSS

2004-08-18 04:00 AM
31
cve
cve

CVE-2004-0487

A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary...

7.5AI Score

0.379EPSS

2004-08-18 04:00 AM
23
cve
cve

CVE-2004-0444

Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service....

8.4AI Score

0.926EPSS

2004-07-07 04:00 AM
30
cve
cve

CVE-2004-0445

The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption....

6.6AI Score

0.92EPSS

2004-07-07 04:00 AM
29
cve
cve

CVE-2004-0364

The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL...

7.4AI Score

0.561EPSS

2004-04-15 04:00 AM
31
cve
cve

CVE-2004-0363

Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard...

7.8AI Score

0.941EPSS

2004-04-15 04:00 AM
31
cve
cve

CVE-2002-0663

Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP...

8.4AI Score

0.003EPSS

2003-04-02 05:00 AM
20
Total number of security vulnerabilities75