Show filters
41 Total Results
Displaying 21-30 of 41
Sort by:
Attacker Value
Unknown
CVE-2016-3650
Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
0
Attacker Value
Unknown
CVE-2016-5304
Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-5306
Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.
0
Attacker Value
Unknown
CVE-2015-8153
Disclosure Date: March 18, 2016 (last updated November 25, 2024)
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-8152
Disclosure Date: March 18, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.
0
Attacker Value
Unknown
CVE-2015-8154
Disclosure Date: March 18, 2016 (last updated November 25, 2024)
The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions."
0
Attacker Value
Unknown
CVE-2015-6555
Disclosure Date: November 12, 2015 (last updated October 05, 2023)
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the console Java port.
0
Attacker Value
Unknown
CVE-2015-6554
Disclosure Date: November 12, 2015 (last updated October 05, 2023)
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data.
0
Attacker Value
Unknown
CVE-2015-1487
Disclosure Date: August 01, 2015 (last updated October 05, 2023)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.
0
Attacker Value
Unknown
CVE-2015-1491
Disclosure Date: August 01, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0