Show filters
599 Total Results
Displaying 61-70 of 599
Sort by:
Attacker Value
Unknown

CVE-2019-12754

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
Symantec My VIP portal, previous version which has already been auto updated, was susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users or potentially bypass access controls such as the same-origin policy.
0
Attacker Value
Unknown

CVE-2019-12753

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authenticated administrator user to obtain passwords for external SMTP, FTP, FTPS, LDAP, and Cloud Log Download servers that they might not otherwise be authorized to access. The malicious administrator user can also obtain the passwords of other Reporter web UI users.
0
Attacker Value
Unknown

CVE-2019-12750

Disclosure Date: July 31, 2019 (last updated November 27, 2024)
Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
0
Attacker Value
Unknown

CVE-2019-12751

Disclosure Date: July 11, 2019 (last updated November 27, 2024)
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
0
Attacker Value
Unknown

CVE-2019-9703

Disclosure Date: July 01, 2019 (last updated November 27, 2024)
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
0
Attacker Value
Unknown

CVE-2019-9702

Disclosure Date: July 01, 2019 (last updated November 27, 2024)
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
0
Attacker Value
Unknown

CVE-2019-9701

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.
0
Attacker Value
Unknown

CVE-2019-9698

Disclosure Date: May 08, 2019 (last updated November 27, 2024)
Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulnerability that could allow an attacker to delete files on the resident system without elevated privileges.
0
Attacker Value
Unknown

CVE-2018-18367

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
0
Attacker Value
Unknown

CVE-2018-18366

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.
0