Show filters
47 Total Results
Displaying 41-47 of 47
Sort by:
Attacker Value
Unknown
CVE-2006-3454
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
0
Attacker Value
Unknown
CVE-2006-1836
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
0
Attacker Value
Unknown
CVE-2005-3270
Disclosure Date: October 21, 2005 (last updated February 22, 2025)
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
0
Attacker Value
Unknown
CVE-2005-2759
Disclosure Date: October 20, 2005 (last updated February 22, 2025)
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use CVE-2005-3270 for the DiskMountNotify issue, and CVE-2005-2759 for the LiveUpdate issue.
0
Attacker Value
Unknown
CVE-2005-2766
Disclosure Date: September 02, 2005 (last updated February 22, 2025)
Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.
0
Attacker Value
Unknown
CVE-2005-2017
Disclosure Date: August 30, 2005 (last updated February 22, 2025)
Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.
0
Attacker Value
Unknown
CVE-2005-0249
Disclosure Date: February 08, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
0