Show filters
68 Total Results
Displaying 41-50 of 68
Sort by:
Attacker Value
Unknown
CVE-2005-2766
Disclosure Date: September 02, 2005 (last updated February 22, 2025)
Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.
0
Attacker Value
Unknown
CVE-2005-2017
Disclosure Date: August 30, 2005 (last updated February 22, 2025)
Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.
0
Attacker Value
Unknown
CVE-2005-0923
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share.
0
Attacker Value
Unknown
CVE-2005-0922
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type.
0
Attacker Value
Unknown
CVE-2005-1346
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid detection via a crafted RAR file.
0
Attacker Value
Unknown
CVE-2005-0249
Disclosure Date: February 08, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
0
Attacker Value
Unknown
CVE-2004-2147
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
0
Attacker Value
Unknown
CVE-2004-0920
Disclosure Date: November 03, 2004 (last updated February 22, 2025)
Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.
0
Attacker Value
Unknown
CVE-2004-0487
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.
0
Attacker Value
Unknown
CVE-2004-0683
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.
0