Show filters
599 Total Results
Displaying 71-80 of 599
Sort by:
Attacker Value
Unknown

CVE-2018-12244

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
0
Attacker Value
Unknown

CVE-2018-18369

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
0
Attacker Value
Unknown

CVE-2019-18379

Disclosure Date: April 18, 2019 (last updated November 27, 2024)
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through the loopback interface.
Attacker Value
Unknown

CVE-2019-9694

Disclosure Date: April 10, 2019 (last updated November 27, 2024)
Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
0
Attacker Value
Unknown

CVE-2019-9696

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
0
Attacker Value
Unknown

CVE-2018-18365

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic.
0
Attacker Value
Unknown

CVE-2019-9695

Disclosure Date: March 29, 2019 (last updated November 27, 2024)
Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that has the potential of allowing an individual to execute arbitrary commands or code on a target machine or in a target process. Note that this exploit is only possible with direct physical access to the device.
0
Attacker Value
Unknown

CVE-2018-18364

Disclosure Date: February 08, 2019 (last updated November 27, 2024)
Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1 may be susceptible to a DLL hijacking vulnerability, which is a type of issue whereby a potential attacker attempts to execute unexpected code on your machine. This occurs via placement of a potentially foreign file (DLL) that the attacker then attempts to run via a linked application.
0
Attacker Value
Unknown

CVE-2018-12237

Disclosure Date: January 24, 2019 (last updated November 27, 2024)
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
0
Attacker Value
Unknown

CVE-2018-18363

Disclosure Date: January 24, 2019 (last updated November 27, 2024)
Norton App Lock prior to 1.4.0.445 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.
0