Show filters
599 Total Results
Displaying 41-50 of 599
Sort by:
Attacker Value
Unknown

CVE-2016-6586

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.
Attacker Value
Unknown

CVE-2016-6588

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.
Attacker Value
Unknown

CVE-2016-6593

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.
Attacker Value
Unknown

CVE-2016-6589

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.
Attacker Value
Unknown

CVE-2016-6590

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2016-6591

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.
Attacker Value
Unknown

CVE-2019-18377

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Attacker Value
Unknown

CVE-2019-18378

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
Attacker Value
Unknown

CVE-2019-18380

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.
Attacker Value
Unknown

CVE-2019-18373

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain access.