Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown

CVE-2018-18367

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
0
Attacker Value
Unknown

CVE-2016-3648

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts, by entering data into the authorization window.
0
Attacker Value
Unknown

CVE-2016-3652

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-8801

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.
0
Attacker Value
Unknown

CVE-2016-3649

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.
0
Attacker Value
Unknown

CVE-2016-3647

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet hosts, via a crafted request.
0
Attacker Value
Unknown

CVE-2016-3651

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover the PHP JSESSIONID value via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-5307

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-3653

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2016-5305

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via a "DOM link manipulation" attack.
0