Show filters
185 Total Results
Displaying 141-150 of 185
Sort by:
Attacker Value
Unknown
CVE-2015-1490
Disclosure Date: August 01, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via a relative pathname in a client installation package.
0
Attacker Value
Unknown
CVE-2015-1486
Disclosure Date: August 01, 2015 (last updated October 05, 2023)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
0
Attacker Value
Unknown
CVE-2015-1489
Disclosure Date: August 01, 2015 (last updated October 05, 2023)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3437
Disclosure Date: November 07, 2014 (last updated October 05, 2023)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2014-3439
Disclosure Date: November 07, 2014 (last updated October 05, 2023)
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3438
Disclosure Date: November 07, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-8518
Disclosure Date: October 29, 2014 (last updated October 05, 2023)
The (1) Removable Media and (2) CD and DVD encryption offsite access options (formerly Endpoint Encryption for Removable Media or EERM) in McAfee File and Removable Media Protection (FRP) 4.3.0.x, and Endpoint Encryption for Files and Folders (EEFF) 3.2.x through 4.2.x, uses a hard-coded salt, which makes it easier for local users to obtain passwords via a brute force attack.
0
Attacker Value
Unknown
CVE-2014-3434
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.
0
Attacker Value
Unknown
CVE-2013-5014
Disclosure Date: February 14, 2014 (last updated October 05, 2023)
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown
CVE-2013-5015
Disclosure Date: February 14, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0